A vulnerability has been identified in Chupix CMS, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "download.php" script that does not validate the "fichier" parameter before being passed as an argument to a "readfile()" call, which could be exploited by attackers to download arbitrary files from a vulnerable server via directory traversal attacks.
Vulnerable Products
Vulnerable Software: Chupix CMS version 0.2.3 and prior