MineAdmin versions before 3.2.0-alpha.2 contain a path traversal vulnerability in the app-store plugin service. The identifier parameter is concatenated into filesystem paths without sanitization.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view