PT-2023-25338 · Elfinder · Elfinder

Sectroyer

·

Publicado

2023-06-14

·

Atualizado

2024-12-12

·

CVE-2023-35840

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions elFinder versions prior to 2.1.62
Description The issue allows path traversal in the PHP LocalVolumeDriver connector due to incomplete validity checking of supplied request parameters. This can be exploited by allowing untrusted users to write to the local file system.
Recommendations For versions prior to 2.1.62, update to elFinder version 2.1.62 as soon as possible to fix the issue. If you cannot update for some reason, consider stopping the use of the vulnerable connector or prohibit writing to untrusted users.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35840
GHSA-3P2Q-MH7Q-9PXJ
GHSA-WM5G-P99Q-66G4

Produtos afetados

Elfinder