connector.minimal.php in std42 elFinder up to and including 2.1.60 is affected by path traversal. This allows unauthenticated remote malicious users to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
std42 elfinder |