CVE-2013-1972

Alexey Sukhotin Elfinder - XSS

Title source: rule

Description

Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.

Scores

EPSS 0.0045
EPSS Percentile 63.4%

Details

CWE
CWE-79
Status published
Products (8)
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
alexey_sukhotin/elfinder
n/a/n/a
Published Jun 24, 2013
Tracked Since Feb 18, 2026