Description
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.
INFO
Published Date :
2026-04-22T18:33:44.084Z
Last Modified :
2026-04-24T19:26:52.848Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-34413 vulnerability.
| Vendors | Products |
|---|---|
| Thexerteproject |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34413.