Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.
| Software | From | Fixed in |
|---|---|---|
| scott_parish / chuid | 1.1 | 1.1.x |
| scott_parish / chuid | 1.2 | 1.2.x |
| scott_parish / chuid | 1.0 | 1.0.x |