Description loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. Remediation References CVE-2022-48285 Related Vulnerabilities MySQL CVE-2020-14643 Vulnerability (CVE-2020-14643) WordPress Plugin WP-Table Reloaded Cross-Site Scripting (1.9.3) Roundcube Multiple Cross-site Request Forgery (CSRF) Vulnerabilities (CVE-2014-9587) Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2014-2571) Telerik Web UI Inadequate Encryption Strength Vulnerability (CVE-2017-11317) Severity High Classification CVE-2022-48285 CWE-22 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Tags Missing Update Known Vulnerabilities