QID 730518

Date Published: 2022-06-09

QID 730518: elFinder File Manager Cross-Site Scripting (XSS) Vulnerability

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI.

Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

Affected Versions: elFinder versions till 2.1.31

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of elFinder by sending a GET request to elfinder.js file and checking the version banner from it.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary javascripts on the target system

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to upgrade to latest elFinder version.

    Vendor References

    CVEs related to QID 730518

    Software Advisories
    Advisory ID Software Component Link
    elFinder URL Logo github.com/Studio-42/elFinder