Grid Columns Button Security Vulnerability!

I recently received an alert from my client that there is a Directory Traversal Security Vulnerability in the grid Columns button that exposes the path to the host root directory.

Anyone else encountered this for other buttons?

I hope Scriptcase can fix this security issue ASAP!

Hi
Can you share any further information about it?

Have you reported it to the SC bug team?

thanks.

Attached report from fortinet. The Column button code exposes the root directory of the webserver.

Thanks,

Which SC version are you using?
When you say grid column button which type of column you mean? I use html image columns as links to other applications but I don’t see those parameters.

Any response from SC bug team until now?

regards.

I’m using version 9.8, previous versions have the same issue.

Its the Columns button on the grid menu.

No response from SC bug team yet.