Description
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Remediation
References
Related Vulnerabilities
WordPress Plugin Forms:3rd-Party Inject Results Cross-Site Scripting (0.2)
WordPress Plugin WP Photo Album Plus Unspecified Vulnerability (7.2.04)
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-38843)
WordPress 5.1.x Multiple Vulnerabilities (5.1 - 5.1.15)
Oracle Database Server CVE-2006-0282 Vulnerability (CVE-2006-0282)