HIGH · 8.6

CVE-2021-23428

This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the gene...

Vulnerability Description

This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
Elfinder.Netcore ProjectElfinder.NetcoreAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23428?

CVE-2021-23428 is a vulnerability with a CVSS score of 8.6 (HIGH). This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the gene...

How severe is CVE-2021-23428?

CVE-2021-23428 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23428?

Check the references section above for vendor advisories and patch information. Affected products include: Elfinder.Netcore Project Elfinder.Netcore.