CVE-2020-29134: Totvs Fluig
High severity, CVSS 8.6. EPSS: 27.6% chance of exploitation in the next 30 days.
The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4
Affected products
- Totvs Fluig: version 1.6.4 only; version 1.6.5 only; version 1.7.0 only
Published 2021-03-05. Last modified 2026-06-17.