CVE-2022-26960
Summary
| CVE | CVE-2022-26960 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-21 17:15:00 UTC |
| Updated | 2022-06-30 19:47:00 UTC |
| Description | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Publications | MISC | www.synacktiv.com | |
| elFinder: The story of a repwning | MISC | www.synacktiv.com | |
| [security:CVE-2022-26960] fix a path traversal issue · Studio-42/elFinder@3b75849 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.