Elfinder.netcore ProjectCVEs & Vulnerabilities
2 CVEs affecting Elfinder.netcore Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
elfinder.netcore 2
CVE-2021-23428CRITICAL
This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal
1 Sep 2021
9.8
CVSS
CVE-2021-23427CRITICAL
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
1 Sep 2021
9.8
CVSS
← PrevPage 1 / 1Next →