barryvdh / elfinder-flysystem-driver

elFinder driver for Flysystem
183 stars 41 forks source link

CVE-2022-27115 (remote code execution) #91

Closed kisuka closed 11 months ago

kisuka commented 12 months ago

In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

https://github.com/Studio-42/elFinder/issues/3458 https://nvd.nist.gov/vuln/detail/CVE-2022-27115

barryvdh commented 11 months ago

If you update with composer you should get the .62 version already. But I've bumped it to make sure it doesn't allow older versions; https://github.com/barryvdh/elfinder-flysystem-driver/commit/d9453b082fb6aba122ebdf2184214d980d07b115