PT-2026-34537 · Thexerteproject · Xerte Online Toolkits

Bootstrapbool

·

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-34415

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.

Fix

RCE

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-34415

Affected Products

Xerte Online Toolkits