CVE-2022-26960
Path Traversal in Studio-42 elFinder through 2.1.60
9.1
CRITICAL
CVSS 3.1
EPSS 51.0%
描述
`connector.minimal.php` in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
如何修補 CVE-2022-26960
要修補 CVE-2022-26960,請將受影響套件升級到下列已修補版本。
- Packagist/studio-42/elfinder—升級至 2.1.61 或更新版本
CVE-2022-26960 正在被利用嗎?
可能 — EPSS 為 51.0%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.1.61
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |