Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7q88-jxvp-9gp2

Опубликовано: 22 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Path Traversal in Studio-42 elFinder through 2.1.60

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

Пакеты

Наименование

studio-42/elfinder

composer
Затронутые версииВерсия исправления

<= 2.1.60

2.1.61

EPSS

Процентиль: 99%
0.79151
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
почти 4 года назад

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

EPSS

Процентиль: 99%
0.79151
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-22