Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34776
HistoryMar 22, 2022 - 4:09 a.m.

Path Traversal

2022-03-2204:09:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
path traversal
studio-42/elfinder
improper handling
absolute file paths
getfullpath function
remote attacker
data access
software

EPSS

0.86

Percentile

98.6%

studio-42/elfinder is vulnerable to path traversal. The vulnerability exists due to improper handling of absolute file paths in the getFullPathfunction. allowing a remote attacker to access data in the system.