CVE

CVE-2021-23407

CVE-2021-23407

This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.

Source: CVE-2021-23407

Exit mobile version