In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/…
mitre·CWE-425·Published 2019-07-19