PT-2023-25338 · Elfinder · Elfinder
Sectroyer
·
Published
2023-06-14
·
Updated
2024-12-12
·
CVE-2023-35840
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
elFinder versions prior to 2.1.62
Description
The issue allows path traversal in the PHP LocalVolumeDriver connector due to incomplete validity checking of supplied request parameters. This can be exploited by allowing untrusted users to write to the local file system.
Recommendations
For versions prior to 2.1.62, update to elFinder version 2.1.62 as soon as possible to fix the issue.
If you cannot update for some reason, consider stopping the use of the vulnerable connector or prohibit writing to untrusted users.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elfinder