Studio 42 elFinder vulnerable to Incorrect Access Control
High severity
GitHub Reviewed
Published
Jul 30, 2024
to the GitHub Advisory Database
•
Updated Oct 25, 2024
Description
Published by the National Vulnerability Database
Jul 30, 2024
Published to the GitHub Advisory Database
Jul 30, 2024
Reviewed
Jul 30, 2024
Last updated
Oct 25, 2024
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
References