Description
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Remediation
References
Related Vulnerabilities
Liferay Portal CVE-2020-13444 Vulnerability (CVE-2020-13444)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1590)
WordPress Plugin PickPlugins Product Slider for WooCommerce Cross-Site Scripting (1.13.21)
WordPress Plugin Widget Control Powered By Everyblock Cross-Site Scripting (1.0.1)