Description
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
Remediation
References
https://hackerone.com/reports/355501
Related Vulnerabilities
CVE-2020-11057 Vulnerability in maven package org.xwiki.platform:xwiki-platform-dashboard-macro
CVE-2017-16008 Vulnerability in maven package org.webjars.bower:i18next
CVE-2016-7103 Vulnerability in npm package jquery-ui
CVE-2023-39156 Vulnerability in maven package org.jenkins-ci.plugins:bazaar
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom