S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 24, 2026

CVE-2026-34413 Scanner

CVE-2026-34413 Scanner - Remote Code Execution vulnerability in Xerte Online Toolkits

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-34413
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
xerteonlinetoolkitsby thexerteproject
0
Updated Sep 10, 2026View on NVD →
Detail

Xerte Online Toolkits is an open-source content authoring tool used primarily by educational institutions for creating and managing interactive learning content. Developed by the University of Nottingham, it provides educators with the tools to design flexible and adaptive digital learning materials. The platform is popular for its user-friendly interface and extensive customization options, making it accessible to both novice and advanced users. Xerte Online Toolkits also supports collaborative content development, allowing multiple users to work on a project simultaneously. As a web-based solution, it integrates easily with existing learning management systems, enhancing the reach and effectiveness of digital education. Its ability to support multimedia content means educators can create rich, engaging learning experiences for students.

The Remote Code Execution vulnerability in Xerte Online Toolkits is a critical security flaw that allows attackers to execute arbitrary PHP code on targeted servers. This vulnerability exists due to improper input validation and lack of adequate authentication mechanisms in the file manager component used by the toolkits. The flaw can be exploited without authentication, providing attackers with unauthorized access to execute commands. The vulnerability is primarily present in versions 3.15 and earlier, exposing these systems to significant security risks. By leveraging this vulnerability, attackers can potentially take full control of affected servers, causing data breaches or service disruption. It's imperative that users of Xerte Online Toolkits update their installations to patch these critical flaws.

The vulnerability specifically resides in the elFinder file manager connector, exposed at /editor/elfinder/php/connector.php. The absence of authentication allows attackers to exploit relative path traversal in elFinder rename commands. This is further exacerbated by an inadequate file-extension blocklist, permitting uploads of potentially malicious files with a .php4 extension. Through a crafted sequence of HTTP requests, an attacker can exploit this weakness to upload and execute PHP scripts on the server. This sequence includes navigating the application's directory structure to place or execute files where they should not be allowed. By taking advantage of these oversights, attackers gain unauthorized execution capabilities over the affected server, posing serious risks to server integrity and security.

Exploitation of this vulnerability could lead to several serious consequences. Primary among these is the execution of arbitrary PHP code, enabling attackers to install backdoors, exfiltrate sensitive data, or disrupt service functionality. This form of attack could lead to data integrity issues or complete data loss. Additionally, after gaining a foothold on the server, an attacker could escalate privileges, leading to further breaches within the same infrastructure. The vulnerability could be used as a stepping stone for more sophisticated attacks or persistent threats within an organization. These potential outcomes underline the importance of prompt patching and securing against such vulnerabilities.

REFERENCES

Solution Advice
  • Update Xerte Online Toolkits to the latest version to address this vulnerability.
  • Implement strict access controls to limit exposure of the connector.php script.
  • Regularly audit and sanitize inputs and file uploads to prevent unauthorized code execution.
  • Enable logging and monitoring to detect and respond to unauthorized access attempts.
  • Review and apply security patches promptly to maintain the system's security posture.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.