Опубликовано: 30 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8
Описание
Studio 42 elFinder vulnerable to Incorrect Access Control
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Пакеты
Наименование
studio-42/elfinder
composer
Затронутые версииВерсия исправления
<= 2.1.64
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
больше 1 года назад
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.