Sean de Regge has reported a vulnerability in JSUpload, which can be exploited by malicious people to disclose certain sensitive information.
Certain input passed to the "writeItemContent()" function is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary files via directory traversal sequences.
The vulnerability is reported in versions prior to 0.6.5.