Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
| Software | From | Fixed in |
|---|---|---|
| alkacon / opencms | 6.0.3 | 6.0.3.x |
| alkacon / opencms | 6.0.4 | 6.0.4.x |
| alkacon / opencms | - | 6.2.1.x |
| alkacon / opencms | 6.0.0 | 6.0.0.x |
| alkacon / opencms | 6.2 | 6.2.x |
| alkacon / opencms | 6.0.2 | 6.0.2.x |