CVE-2023-52045: XSS
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52045?
CVE-2023-52045 is classified as a high severity vulnerability due to its ability to lead to persistent Cross-site Scripting (XSS).
How do I fix CVE-2023-52045?
To fix CVE-2023-52045, update to the latest version of Studio-42 eLfinder that addresses the filename restriction bypass issue.
What causes CVE-2023-52045?
CVE-2023-52045 is caused by a vulnerability in Studio-42 eLfinder where filename restrictions can be bypassed, allowing for malicious scripts to be executed.
Who is affected by CVE-2023-52045?
Anyone using Studio-42 eLfinder version 2.1.62 is potentially affected by CVE-2023-52045.
What is the impact of CVE-2023-52045?
The impact of CVE-2023-52045 includes the potential for attackers to execute arbitrary JavaScript in the context of an affected user's session.