Directory traversal vulnerability in json.php in TomatoCart 1.2.0 Alpha 2 and possibly earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter in a "3" action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.143
EPSS Ranking 94.1%