Vulnerability record · CVE-2022-26960 · published 21 March 2022
CVE-2022-26960: elFinder path traversal in connector.minimal.php allows file access outside root
Std42 · Elfinder
connector.minimal.php in std42 elFinder through 2.1.60 mishandles absolute file paths, enabling path traversal. Unauthenticated remote attackers can read, write, and browse files outside the configured document root, so any exposed instance is at risk of full file-system manipulation within the web server's permissions.
Description
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute file paths.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or user interaction required and high EPSS, allowing unauthenticated read and write outside the document root.
What it is
connector.minimal.php in std42 elFinder through 2.1.60 mishandles absolute file paths, enabling path traversal. Unauthenticated remote attackers can read, write, and browse files outside the configured document root, so any exposed instance is at risk of full file-system manipulation within the web server's permissions.
Impact
An attacker gains unauthenticated read and write access to files outside the document root, which can lead to source or configuration disclosure and to planting files that enable further compromise.
Attack surface
Reachable over the network through the connector.minimal.php endpoint; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.50993, 98.9th percentile) and public references include an exploit and technical description, indicating known exploitation techniques are documented.
What to do
- Upgrade elFinder past 2.1.60 to the patched release referenced in the vendor commit.
- If immediate upgrade is not possible, restrict or disable network access to connector.minimal.php.
- Run the web service with least privilege and confine its file-system permissions to the intended document root.
- Validate and canonicalize file paths server-side, rejecting absolute paths and traversal sequences.
- Monitor the connector endpoint for anomalous file access patterns until patched.
Detection
- Review web server logs for requests to connector.minimal.php with absolute or traversal-style path parameters.
- Alert on file reads or writes outside the configured document root by the web server process.
- Monitor for unexpected new files or modifications in web-accessible directories.
- Correlate connector endpoint access with subsequent suspicious file activity on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Studio-42/elFinder/commit/3b758495538a448ac8830ee3559e7fb2c260c6db | PatchThird Party Advisory |
| https://www.synacktiv.com/publications.html | Product |
| https://www.synacktiv.com/publications/elfinder-the-story-of-a-repwning.html | ExploitTechnical DescriptionThird Party Advisory |
| https://github.com/Studio-42/elFinder/commit/3b758495538a448ac8830ee3559e7fb2c260c6db | PatchThird Party Advisory |
| https://www.synacktiv.com/publications.html | Product |
| https://www.synacktiv.com/publications/elfinder-the-story-of-a-repwning.html | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2022-26960 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-26960), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.