In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint handler.
| Software | From | Fixed in |
|---|---|---|
erxes
|
- | 1.6.2 |
| erxes / erxes | - | 1.6.2 |