CVE-2013-1972
Alexey Sukhotin Elfinder - XSS
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.
References (6)
Scores
EPSS
0.0045
EPSS Percentile
63.4%
Details
CWE
CWE-79
Status
published
Products (8)
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
n/a/n/a
Published
Jun 24, 2013
Tracked Since
Feb 18, 2026