A vulnerability has been identified in MuddyDogPaws FileDownload, which could be exploited by attackers to gain knowledge of sensitive information. This issue is due to an input validation error in the "download.php" script that does not validate user-supplied parameters, which could be exploited by malicious users to download arbitrary files from a vulnerable web server.
Vulnerable Products
Vulnerable Software: MuddyDogPaws FileDownload (snippet for MODx) versions prior to 2.5