NA

CVE-2023-35840

Published: 19/06/2023 Updated: 26/06/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder prior to 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

Vulnerable Product Search on Vulmon Subscribe to Product

std42 elfinder

Github Repositories

elFinder < 2.1.62 - Path Traversal vulnerability in PHP LocalVolumeDriver connector

CVE-2023-35840 elFinder &lt; 2162 - Path Traversal vulnerability in PHP LocalVolumeDriver connector Description Path Traversal vulnerability in PHP LocalVolumeDriver connector This vulnerability can be exploited by allowing untrusted users to write to the local file system Vulnerability exists in target parameter which contains a base64 encoded path For exmpample path