chamilo/pclzip is vulnerable to Zip Slip
75
High Risk
Affected versions of this package are vulnerable to Zip Slip / Zip Traversal attacks during archive extraction. An attacker can craft a malicious zip archive containing files with '../' or '..\' in their filenames, allowing extraction routines to write files outside the intended extraction directory. This can result in overwriting critical files or writing to restricted locations on the file system.
You are affected if you are using a version that falls within the vulnerable range.
chamilo/pclzip is vulnerable to Zip Slip in versions 2.8.3 - 2.8.4.
Upgrade the chamilo/pclzip library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant