Flextype v1.0.0-alpha.3 Stored... Note

Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read

Posted by Ron E on Sep 03Description Flextype CMS v1.0.0-alpha.3 contains an arbitrary file-read vulnerability in its stored shortcode processing functionality. Attacker-controlled entry fields are automatically processed by the shortcode parser when global shortcode processing is enabled. The built-in filesystem shortcode accepts a file path and returns the contents of the specified file without restricting the path to an approved application directory. An attacker...