THREAT OPS › Threat News › Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure
Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure
<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains a path traversal vulnerability in the<br /> Entries copy functionality. An authenticated remote attacker can supply<br /> directory traversal sequences within both the source id and destination<br /> new_id parameters submitted to /api/v1/entries/copy.<br /> <br /> Flextype constructs entry directory path
Original source: https://seclists.org/fulldisclosure/2026/Sep/22