In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal. References https://nvd.nist.gov/vuln/detail/CVE-2022-30427 https://github.com/gphper/ginadmin/issues/8 https://github.com/gphper/ginadmin/commit/726109f01ad23523715f36f7d272958064666a30 https://github.com/advisories/GHSA-9pg5-3pjc-f8wm