PT-2026-34537 · Unknown · Xerte Online Toolkits

Bootstrapbool

·

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-34415

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xerte Online Toolkits versions 3.15 and earlier
Description Incomplete input validation in the elFinder connector endpoint fails to block PHP-executable extensions such as .php4 due to an incorrect regex pattern. Unauthenticated attackers can combine this flaw with authentication bypass and path traversal to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.
Recommendations Update to a version later than 3.15.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34415

Affected Products

Xerte Online Toolkits