Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
{
"severity": "HIGH",
"github_reviewed_at": "2024-07-30T17:12:00Z",
"cwe_ids": [
"CWE-284"
],
"nvd_published_at": "2024-07-30T14:15:02Z",
"github_reviewed": true
}