QID 981111
QID 981111: Dotnet (nuget) Security Update for elFinder.NetCore (GHSA-9rjp-r58j-fxgq)
This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9rjp-r58j-fxgq for updates pertaining to this vulnerability.
Vendor References
- GHSA-9rjp-r58j-fxgq -
github.com/advisories/GHSA-9rjp-r58j-fxgq
CVEs related to QID 981111
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9rjp-r58j-fxgq | elFinder.NetCore |
|