HTTP: Studio-42 elFinder getFullPath Directory Traversal

This signature detects attempts to exploit a known vulnerability against Studio-42 application. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

Affected Products

Std42 elfinder

Short Name
HTTP:DIR:STUDIO-42-ELFINDER
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2022-26960 Directory Studio-42 Traversal elFinder getFullPath
Release Date
04/19/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3484
False Positive
Unknown
Vendors

Std42

CVSS Score

6.4

Found a potential security threat?