CVE-2023-35840
MEDIUMelFinder < 2.1.62 - Path Traversal via LocalVolumeDriver Connector
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-35840. PoCs published by afine-com.
AI-analyzed exploit summary The repository describes a path traversal vulnerability in elFinder's PHP LocalVolumeDriver connector, where the `target` parameter can be manipulated via base64 encoding to write arbitrary files to the application root. The issue is fixed in version 2.1.62.
Description
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
Exploits (1)
The repository describes a path traversal vulnerability in elFinder's PHP LocalVolumeDriver connector, where the `target` parameter can be manipulated via base64 encoding to write arbitrary files to the application root. The issue is fixed in version 2.1.62.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N