PT-2026-50545 · Typemill · Typemill
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Typemill versions prior to 2.24.0
Description
Authenticated attackers with Author-level privileges can read arbitrary files outside the content directory. This is possible by supplying traversal sequences in the
path query parameter passed to the getFile() function within the Storage class when an empty folder argument is used. This action bypasses the traversal-prevention controls implemented in the getFolderPath() function.Recommendations
Update to version 2.24.0 or later.
As a temporary workaround, restrict access to the
getFile() function or monitor the path parameter for traversal sequences.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typemill