CVE-2017-14196: Squiz Matrix

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

Affected products

  • Squiz Matrix: from 5.3.0.0, up to and including 5.3.6.1; version 5.4.1.3 only

Published 2017-11-30. Last modified 2026-06-17.