Логотип exploitDog
bind:CVE-2022-26960
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-26960

Количество 2

Количество 2

nvd логотип

CVE-2022-26960

почти 4 года назад

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

CVSS3: 9.1
EPSS: Высокий
github логотип

GHSA-7q88-jxvp-9gp2

почти 4 года назад

Path Traversal in Studio-42 elFinder through 2.1.60

CVSS3: 9.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-26960

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

CVSS3: 9.1
79%
Высокий
почти 4 года назад
github логотип
GHSA-7q88-jxvp-9gp2

Path Traversal in Studio-42 elFinder through 2.1.60

CVSS3: 9.1
79%
Высокий
почти 4 года назад

Уязвимостей на страницу