GHSA-3p2q-mh7q-9pxj
Dashboard / Vulnerabilities / GHSA-3p2q-mh7q-9pxj
GHSA-3p2q-mh7q-9pxj
Summary: Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector
Details: ### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wm5g-p99q-66g4. This link is maintained to preserve external references. ### Original Description _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
References: https://github.com/Studio-42/elFinder/security/advisories/GHSA-wm5g-p99q-66g4, https://nvd.nist.gov/vuln/detail/CVE-2023-35840, https://github.com/Studio-42/elFinder/commit/bb9aaa7b096a1b83f2f85657c43f12131ece2891
Affected packages
Package
Name: studio-42/elfinder
Purl: pkg:composer/studio-42/elfinder
Affected ranges
Type: ECOSYSTEM
Events:
