MPXJ path Traversal vulnerability
Moderate severity
GitHub Reviewed
Published
Dec 18, 2020
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Dec 14, 2020
Reviewed
Dec 17, 2020
Published to the GitHub Advisory Database
Dec 18, 2020
Last updated
Jan 30, 2023
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
References