An attacker could access files outside of Duplicator’s intended directory by submitting values like ../../../file.php to navigate throughout the server’s file structure.
This vulnerability affects the following application versions:
- Duplicator 1.3.24
- Duplicator 1.3.26
SOCIAL SHARE CARD GENERATOR