Unsafe filtering makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work.
This vulnerability affects the following application versions:
- Duplicator 1.3.0
- Duplicator 1.3.2
- Duplicator 1.3.4
- Duplicator 1.3.6
- Duplicator 1.3.8
- Duplicator 1.3.10
- Duplicator 1.3.12
- Duplicator 1.3.14
- Duplicator 1.3.16
- Duplicator 1.3.18
- Duplicator 1.3.20
- Duplicator 1.3.22
- Duplicator 1.3.24
- Duplicator 1.3.26
- Duplicator 1.3.28
- Duplicator 1.3.30
- Duplicator 1.3.32
- Duplicator 1.3.34
- Duplicator 1.3.36
- Duplicator 1.3.38
- Duplicator 1.3.40
- Duplicator 1.3.40.1
- Duplicator 1.4.0
- Duplicator 1.4.1
- Duplicator 1.4.2
- Duplicator 1.4.3
- Duplicator 1.4.4
- Duplicator 1.4.5
- Duplicator 1.4.6
- Duplicator 1.4.7
- Duplicator 1.4.7.1
- Duplicator 1.4.7.2
- Duplicator 1.5.0
- Duplicator 1.5.1
- Duplicator 1.5.2
- Duplicator 1.5.2.1
- Duplicator 1.5.3
- Duplicator 1.5.3.1
- Duplicator 1.5.4
- Duplicator 1.5.5
- Duplicator 1.5.5.1
- Duplicator 1.5.6
- Duplicator 1.5.6.1
- Duplicator 1.5.7
- Duplicator 1.5.7.1
- Duplicator 1.5.8
- Duplicator 1.5.8.1
- Duplicator 1.5.9