Erxes Path Traversal vulnerability
High severity
GitHub Reviewed
Published
Jun 10, 2025
to the GitHub Advisory Database
•
Updated Jun 10, 2025
Description
Published by the National Vulnerability Database
Jun 10, 2025
Published to the GitHub Advisory Database
Jun 10, 2025
Reviewed
Jun 10, 2025
Last updated
Jun 10, 2025
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.
References