A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially crafted path in the 'edit-file' parameter.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-26T23:21:14Z",
"nvd_published_at": "2025-12-26T17:15:42Z",
"severity": "HIGH"
}