An attacker can exploit these issues to delete, upload, and download arbitrary files within the context of the affected application, to obtain potentially sensitive information from local files, and to execute arbitrary local scripts in the context of the Web server process; other attacks are also possible.WebPagetest 2.6 and prior versions are vulnerable.
Vendor Status:
Currently we are not aware of any vendor-supplied patches