MEDIUM
GHSA-2977-5php-6789
Erxes Path Traversal vulnerability
Quick fix
GHSA-2977-5php-6789 — erxes: upgrade to the fixed version with the command below.
npm install erxes@1.6.2Details
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCreate GraphQL mutation handler.
Are you affected?
Enter the version of the package you're using.