Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read
Posted by Ron E on Sep 03Description Flextype CMS v1.0.0-alpha.3 contains an arbitrary file-read vulnerability
in its stored shortcode processing functionality. Attacker-controlled entry
fields are automatically processed by the shortcode parser when global
shortcode processing is enabled. The built-in filesystem shortcode accepts a file path and returns the
contents of the specified file without restricting the path to an approved
application directory. An attacker...