phpmussel/frontend is vulnerable to Path Traversal
55
Medium Risk
Affected versions of this package are vulnerable to Path Traversal via getAssetPath due to inadequate sanitization of user-controlled GET parameters passed to getAssetPath calls during frontend asset rendering. Attackers can exploit this by manipulating input fields to inject directory traversal sequences, tricking the system into accessing or exposing files outside the intended asset directory. Successful exploitation allows unauthorized reading of sensitive server files, potentially leading to information disclosure, authentication bypass, or server compromise.
You are affected if you are using a version that falls within the vulnerable range.
phpmussel/frontend is vulnerable to Path Traversal in versions 3.0.0 - 3.6.2.
Upgrade the phpmussel/frontend library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant