PT-2023-25338 · Elfinder · Elfinder

Sectroyer

·

Published

2023-06-14

·

Updated

2024-12-12

·

CVE-2023-35840

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions elFinder versions prior to 2.1.62
Description The issue allows path traversal in the PHP LocalVolumeDriver connector due to incomplete validity checking of supplied request parameters. This can be exploited by allowing untrusted users to write to the local file system.
Recommendations For versions prior to 2.1.62, update to elFinder version 2.1.62 as soon as possible to fix the issue. If you cannot update for some reason, consider stopping the use of the vulnerable connector or prohibit writing to untrusted users.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-35840
GHSA-3P2Q-MH7Q-9PXJ
GHSA-WM5G-P99Q-66G4

Affected Products

Elfinder