Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Elfinder
(Std42)Repositories | https://github.com/Studio-42/elFinder |
#Vulnerabilities | 13 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2024-07-30 | CVE-2024-38909 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc. | Elfinder | N/A | ||
2023-06-19 | CVE-2023-35840 | _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector. | Elfinder | 6.5 | ||
2021-06-13 | CVE-2021-23394 | The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP. | Elfinder | 9.8 |