Updated January 9th, 2020
This module enables you to import taxonomy terms from different sources, including a text area, a file upload or a file present in the web server.
The module doesn't sufficiently validate user input when providing a local
filename to import.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "import taxonomy by csv".
Original advisory: