Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
VikAppointments Booking Calendar (<=1.2.21) has a CRITICAL path traversal bug — unauth attackers could delete server files, risking RCE. Audit your File-type fields and restrict access now. Details: https://radar.offseq.com/threat/cve-2026-87115-cwe-22-improper-limitation-of-a-pathname-to-a-restr...
https://radar.offseq.com/threat/cve-2026-87115-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-59a71fc6e6540921
2026-10-03T07:30:25.057Z