Record summary

CVE-2022-26960 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.1.61 · Fixed in 2.1.61affected

Nuclei templates

1
ProjectDiscoveryCRITICALelFinder <=2.1.60 - Local File InclusionCVSS 9.1

elFinder through 2.1.60 is affected by local file inclusion via connector.minimal.php. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, remote code execution, and potential compromise of the entire system.

Remediation

Upgrade elFinder to version 2.1.61 or later to mitigate this vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscve2022cvelfielfinderstd42vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4