In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.
| Software | From | Fixed in |
|---|---|---|
erxes
|
- | 1.6.2 |
| erxes / erxes | - | 1.6.2 |