CVE-2022-26960: Path Traversal
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26960?
CVE-2022-26960 has been classified as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2022-26960?
To fix CVE-2022-26960, it's essential to upgrade to elFinder version 2.1.61 or later, which addresses the path traversal vulnerability.
Who is affected by CVE-2022-26960?
CVE-2022-26960 affects users of versions of std42 elFinder prior to 2.1.61.
What can attackers do with CVE-2022-26960?
Attackers exploiting CVE-2022-26960 can read, write, and browse files outside of the document root, leading to potential data disclosure.
Is authentication required to exploit CVE-2022-26960?
No, CVE-2022-26960 can be exploited by unauthenticated remote attackers.