CVE-2018-9109: Path Traversal
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
Other sources
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/studio-42/elfinderto a version that resolves this vulnerability.Fixed in 2.1.36
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9109?
CVE-2018-9109 has a high severity level due to its potential to allow remote attackers to access and delete sensitive files.
How do I fix CVE-2018-9109?
To fix CVE-2018-9109, upgrade to elFinder version 2.1.36 or later.
What systems are affected by CVE-2018-9109?
CVE-2018-9109 affects all versions of elFinder prior to 2.1.36.
What is the nature of the vulnerability in CVE-2018-9109?
CVE-2018-9109 is a directory traversal vulnerability that allows attackers to download and delete files on the server.
Can CVE-2018-9109 lead to data loss?
Yes, CVE-2018-9109 can lead to data loss as it allows unauthorized file deletion by exploiting the vulnerability.