Description
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin 2Way VideoCalls and Random Chat-HTML5 Webcam Videochat Cross-Site Scripting (5.2.7)
WordPress Plugin Joy Of Text Lite-SMS messaging for WordPress SQL Injection (2.3.0)
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.5)
WordPress Plugin Pinterest 'Pin It' Button Cross-Site Scripting (2.0.8)
WordPress Plugin 3D Banner Rotator 'upload.php' Arbitrary File Upload (2.1)