CVE-2021-23428

HIGH

elFinder.NetCore - Path Traversal via Path.Combine

Title source: llm
STIX 2.1

Description

This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal

Scores

CVSS v3 8.6
EPSS 0.0075
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-22
Status published
Products (2)
elfinder.netcore_project/elfinder.netcore
nuget/elFinder.NetCore 0NuGet
Published Sep 01, 2021
Tracked Since Feb 18, 2026