Medium severity6.5NVD Advisory· Published Jun 19, 2023· Updated Jun 17, 2026
CVE-2023-35840
CVE-2023-35840
Description
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
studio-42/elfinderPackagist | < 2.1.62 | 2.1.62 |
Affected products
2- elFinder/elFinderdescription
Patches
Vulnerability mechanics
References
4- github.com/Studio-42/elFinder/commit/bb9aaa7b096a1b83f2f85657c43f12131ece2891nvdPatchVendor AdvisoryWEB
- github.com/Studio-42/elFinder/security/advisories/GHSA-wm5g-p99q-66g4nvdExploitVendor AdvisoryWEB
- github.com/sectroyer/CVEs/tree/main/CVE-2023-35840nvdExploitThird Party Advisory
- github.com/advisories/GHSA-wm5g-p99q-66g4ghsaADVISORY
News mentions
0No linked articles in our index yet.