Description
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WHIZZ Cross-Site Scripting (1.0.7)
Elgg URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11016)
WordPress Plugin Caldera Forms-More Than Contact Forms Arbitrary File Disclosure (1.8.1)
axios Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28168)