CVE-2018-9110

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-9110
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-9110.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-9110
Aliases
Published
2018-03-28T14:29:00Z
Modified
2025-07-01T06:29:16.965981Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an incomplete fix for CVE-2018-9109.

References

Affected packages

Git / github.com/studio-42/elfinder

Affected ranges

Type
GIT
Repo
https://github.com/studio-42/elfinder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.0.1
1.1

2.*

2.0-beta
2.0-rc1
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.3
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9