CVE-2020-29134: Totvs Fluig

High severity, CVSS 8.6. EPSS: 27.6% chance of exploitation in the next 30 days.

The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

Affected products

  • Totvs Fluig: version 1.6.4 only; version 1.6.5 only; version 1.7.0 only

Published 2021-03-05. Last modified 2026-06-17.