S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-26960 Scanner

Detects 'Path Traversal' vulnerability in elFinder affects v. through 2.1.60.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-26960
9.1
CVSS

connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ElFinder is an open-source web-based file manager used primarily in web applications to manage and organize files. It is available for free on the internet and is compatible with a vast array of web browsers. ElFinder provides an easy-to-use interface that enables users to upload, download, rename, and delete files. The application has become popular for its flexibility and robustness, making it an essential tool for managing digital assets in modern websites and web applications.

An alarming security vulnerability has been detected in the standard elFinder through version 2.1.60. The CVE-2022-26960 vulnerability exposes web applications to path traversal attacks, consequently risking the confidentiality and integrity of    files    on    servers. Path traversal, also known as directory traversal, is a known web application vulnerability and enables attackers to gain unauthorized access to files outside the intended directory. Attackers can exploit this vulnerability remotely without authentication, accessing, reading, writing, and browsing files outside the configured document root.

When exploited, the CVE-2022-26960 vulnerability can result in dire consequences for web applications. Attackers can access sensitive files with confidential data, potentially compromising the web application and the server. Attackers can also upload malicious files or overwrite system files with compromised ones, resulting in system failure or unauthorized access. Exploiting the vulnerability can also result in denial of service attacks, disabling web applications or servers.

In conclusion, with s4e.io's pro features, users can easily and comprehensively learn about vulnerabilities in their digital assets. Thanks to its robust platform, users can identify and address web application vulnerabilities, such as the CVE-2022-26960 found in elFinder, in an efficient and timely manner. Stay protected, secure, and confident, knowing that your digital assets are always monitored and protected.

 

REFERENCES

Solution Advice

To prevent this vulnerability, there are several precautions that you can take when using elFinder in your web application. 

  • Always update to the latest version of elFinder to ensure vulnerabilities are patched
  • Avoid using absolute file paths and instead use relative file paths
  • Implement proper file and directory permissions on your server
  • Use access control list (ACL) and restrict access to authorized users only
  • Implement a web application firewall to detect and block access attempts to sensitive files 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.