CVE-2021-23407: Directory Traversal
Published Jul 14, 2021
·Updated
This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.
Affected Software
1 affected component
Elfinder.net.core Project Elfinder.net.core<1.2.4
Remediation
Patch Available
Event History
Jul 14, 2021
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-23407?
CVE-2021-23407 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2021-23407?
To fix CVE-2021-23407, upgrade elFinder.Net.Core to version 1.2.4 or later.
3
What types of attacks can CVE-2021-23407 facilitate?
CVE-2021-23407 can facilitate path traversal attacks due to inadequate file name sanitization.
4
Which versions of elFinder.Net.Core are affected by CVE-2021-23407?
CVE-2021-23407 affects all versions of elFinder.Net.Core prior to 1.2.4.
5
Is user input vulnerable in CVE-2021-23407?
Yes, user-controlled file names in CVE-2021-23407 are not properly sanitized, leading to potential vulnerabilities.