The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-05T15:50:35

Updated: 2021-05-21T19:44:55

Reserved: 2020-11-27T00:00:00


Link: CVE-2020-29134

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-05T16:15:12.740

Modified: 2022-07-30T03:49:07.630


Link: CVE-2020-29134

JSON object: View

cve-icon Redhat Information

No data.

CWE