Описание
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:std42:elfinder:2.1.64:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00476
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-284
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
Studio 42 elFinder vulnerable to Incorrect Access Control
EPSS
Процентиль: 39%
0.00476
Низкий
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-284