THREAT OPS › Threat News › [GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversal
[GHSA] GHSA-7hxc-f267-h5q7 (low) — Craft CMS: Incorrect path validation could potentially lead to path traversal
GHSA-7hxc-f267-h5q7 Severity: low CVE: None
Craft CMS: Incorrect path validation could potentially lead to path traversal
The `ensurePathIsContained` function of the `Local` file system class is theoretically vulnerable to path traversal, although no exploitable scenario has been discovered.
When a file is read, an `Asset` object uses the `getFileStream` method of the `Volume` where the asset f
Original source: https://github.com/advisories/GHSA-7hxc-f267-h5q7