Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the type parameter. NOTE: this vulnerability can be leveraged to upload arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.161
EPSS Ranking 94.5%