The application doesn't perform a check/filter against the value of "importFile" parameter at endpoint "/admin/translation/import". After the API is executed, PHP unlink function will proceed to delete the file.
{ "nvd_published_at": "2022-02-22T15:15:00Z", "github_reviewed_at": "2022-03-02T21:16:04Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-22" ] }