Imporoper path validation in elFinder.NetCore
Critical severity
GitHub Reviewed
Published
Sep 2, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Sep 1, 2021
Reviewed
Sep 2, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Jan 27, 2023
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
References