Absolute path traversal vulnerability in downloadTrigger.jsp in Alkacon OpenCms before 6.2.2 allows remote authenticated users to download arbitrary files via an absolute pathname in the filePath parameter.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.opencms:opencms-core(Maven) | 0 | 6.2.2 | N/A |
CVSS Metrics