CVE-2026-34414

HIGH

Xerte Online Toolkits Path Traversal via connector.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-34414. Includes Metasploit module exploits/multi/http/xerte_unauthenticated_mediaupload.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Xerte Online Toolkits by bypassing authentication, extension blacklists, and path traversal restrictions to upload and execute a PHP shell.

Description

Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value containing directory traversal sequences to move files from project media directories to arbitrary locations on the filesystem, potentially overwriting application files, achieving stored cross-site scripting, or combining with other vulnerabilities to achieve unauthenticated remote code execution by moving PHP code files to the application root.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/xerte_unauthenticated_mediaupload.rb

This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Xerte Online Toolkits by bypassing authentication, extension blacklists, and path traversal restrictions to upload and execute a PHP shell.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Xerte Online Toolkits versions 3.15 (commit 4e40f8030a2e3267267db7ce03e0ff57270be6f5) and earlier
No auth needed
Prerequisites: Access to the target's /editor/elfinder/php/connector.php endpoint · PHP execution environment on the target
devstral-2 · analyzed Jun 16, 2026 Full analysis →

Scores

CVSS v3 7.1
EPSS 0.0225
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (7)
thexerteproject/xerteonlinetoolkits < 02661be88cc369325ea01b508086bde7fbfec805
thexerteproject/xerteonlinetoolkits < 17e4f945fe6a3400fa88c01eda18c1075ee4a212
thexerteproject/xerteonlinetoolkits < 3.15.0
thexerteproject/xerteonlinetoolkits < 507d55c5e91bf9310b5b1c7fad8aebfef902ad23
thexerteproject/xerteonlinetoolkits 3.13.0
thexerteproject/xerteonlinetoolkits 3.14.0
thexerteproject/xerteonlinetoolkits 3.15.0
Published Apr 22, 2026
Tracked Since Apr 23, 2026