CVE-2023-35840: Path Traversal
Published Jun 19, 2023
·Updated
joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
Affected Software
1 affected component
std42 elFinder<2.1.62
Remediation
Event History
Jun 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-35840?
CVE-2023-35840 has a high severity rating due to its potential for unauthorized file access through path traversal.
2
How do I fix CVE-2023-35840?
To fix CVE-2023-35840, upgrade to elFinder version 2.1.62 or later.
3
What systems are affected by CVE-2023-35840?
CVE-2023-35840 affects elFinder versions prior to 2.1.62 on systems using the PHP LocalVolumeDriver connector.
4
What exploit methods are associated with CVE-2023-35840?
CVE-2023-35840 can be exploited using path traversal techniques to access unauthorized file directories.
5
Is a patch available for CVE-2023-35840?
Yes, a patch has been included in elFinder version 2.1.62 to address CVE-2023-35840.