connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-21T16:52:38

Updated: 2024-08-03T05:18:38.390Z

Reserved: 2022-03-12T00:00:00

Link: CVE-2022-26960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-03-21T17:15:07.740

Modified: 2022-06-30T19:47:16.823

Link: CVE-2022-26960

cve-icon Redhat

No data.