CVE-2017-14196: Squiz Matrix
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.
Affected products
- Squiz Matrix: from 5.3.0.0, up to and including 5.3.6.1; version 5.4.1.3 only
Published 2017-11-30. Last modified 2026-06-17.