Known CVE
elFinder <=2.1.60 - Local File Inclusion
elFinder through 2.1.60 is affected by local file inclusion via connector.minimal.php. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
CVE-2022-26960
Critical2022CVSS 9.1CWE-22
cve2022 · lfi · elfinder · std42 · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website