CVE-2018-11248: Liulishuo Filedownloader
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.
Affected products
- Liulishuo Filedownloader: version 1.7.3 only
Published 2018-05-18. Last modified 2026-06-17.