Description
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local file path and then download the specified file from the system by requesting the stored document ID. This issue affects Flipper: 3.1.2.
Problem types
CWE-73: External Control of File Name or Path
Product status
3.1.2
Credits
Lockheed Martin Red Team
References
support.opentext.com/...henticated&sysparm_article=KB0850531