Description
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-0423 Vulnerability (CVE-2013-0423)
Oracle Database Server CVE-2011-0877 Vulnerability (CVE-2011-0877)
WordPress Plugin Simple Link Directory Cross-Site Scripting (7.3.4)
WordPress Plugin Recipe Card Blocks for Gutenberg & Elementor Cross-Site Scripting (2.8.0)
WordPress Plugin User Registration, Login & Landing Pages-LeadMagic Cross-Site Scripting (1.2.7)