Impact
Authenticated Control Panel users could read arbitrary .json, .yaml, and .csv files from the server by manipulating the file dictionary's filename configuration parameter in the fieldtype's endpoint.
Patches
This has been fixed in 5.73.14 and 6.7.0.
Impact
Authenticated Control Panel users could read arbitrary
.json,.yaml, and.csvfiles from the server by manipulating the file dictionary'sfilenameconfiguration parameter in the fieldtype's endpoint.Patches
This has been fixed in 5.73.14 and 6.7.0.