Description
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.
References
github.com/harry0703/MoneyPrinterTurbo
gist.github.com/Theresasu1/3a9ced1f3d8208cc9f99ce34057cf681
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.
github.com/harry0703/MoneyPrinterTurbo
gist.github.com/Theresasu1/3a9ced1f3d8208cc9f99ce34057cf681