TOTVS Fluig platform contains a path traversal caused by base64-encoded manipulation of the 'file' parameter, letting attackers access arbitrary files, exploit requires attacker to control the 'file' parameter.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view