Skip to main content

CVE-2023-35840

Description

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

NVD
Severity: MEDIUM
CVE ID: CVE-2023-35840
CVSS Score: 6.5
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Refrence: NVDMITRE

Proof Of Concept

afine-com

elFinder < 2.1.62 - Path Traversal vulnerability in PHP LocalVolumeDriver connector

Refrence: GitHub