Vendor
MineAdmin versions before 3.2.0-alpha.2 contain a path traversal vulnerability in the app-store plugin service allowing authenticated attackers to interact with arbitrary file system directories.