Description
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Remediation
References
Related Vulnerabilities
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
WordPress Plugin Facebook Like Box Multiple Vulnerabilities (2.9.1)
WordPress Plugin GD Rating System Cross-Site Scripting (2.0.2)
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)