VYPR

Fluig

by Totara

CVEs (2)

  • CVE-2020-29134HigMar 5, 2021
    risk 0.57cvss 8.6epss 0.15

    The TOTVS Fluig platform allows path traversal through the parameter "file = .. /" encoded in base64. This affects all versions Fluig Lake 1.7.0, Fluig 1.6.5 and Fluig 1.6.4

  • CVE-2023-6275LowNov 24, 2023
    risk 0.23cvss 3.5epss 0.02

    A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobileredir/openApp.jsp of the component mobileredir. The manipulation of the argument redirectUrl/user…