Vulnerability to directory traversal is available which makes it possible for authenticated attackers, with administrator-level access and above, to perform actions on files outside of the originally intended directory.
This vulnerability affects the following application versions:
- Smush 3.8.3
- Smush 3.8.4
- Smush 3.8.5
- Smush 3.8.7
- Smush 3.8.8
- Smush 3.9.0
- Smush 3.9.1
- Smush 3.9.2
- Smush 3.9.4
- Smush 3.9.5
- Smush 3.9.8
- Smush 3.9.9
- Smush 3.9.11
- Smush 3.10.1
- Smush 3.10.2
- Smush 3.10.3
- Smush 3.11.1
- Smush 3.12.3
- Smush 3.12.4
- Smush 3.12.5
- Smush 3.12.6
- Smush 3.13.0
- Smush 3.13.1
- Smush 3.13.2
- Smush 3.14.0
- Smush 3.14.1
- Smush 3.14.2
- Smush 3.15.0
- Smush 3.15.1
- Smush 3.15.2
- Smush 3.15.3
- Smush 3.15.4
- Smush 3.15.5
- Smush 3.16.2
- Smush 3.16.4
- Smush 3.16.5
- Smush 3.16.6
- Smush 3.17.0