← volver
CVE-2026-34415criticalCWE-184

Xerte Online Toolkits File Upload RCE via elfinder Connector

63Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 9.3epss 3.6%
de la publicación al arma0 días
Publicada en NVD22 abr
metasploit22 abr
probabilidad de explotación
3.6%top 12% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.