Xerte Online Toolkits是英国Xerte公司的一个在线学习内容制作平台。 Xerte Online Toolkits 3.15及之前版本存在安全漏洞,该漏洞源于/editor/elfinder/php/connector.php端点的elFinder连接器缺少身份验证,HTTP重定向未调用exit或die,导致PHP继续执行完整请求,未经身份验证的攻击者可对项目媒体目录执行文件操作,包括创建目录、上传文件、重命名文件、复制文件、覆盖文件和删除文件,结合路径遍历和扩展阻止列表漏洞可能导致远
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| thexerteproject | xerteonlinetoolkits | ≤ 3.15.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thexerteproject | xerteonlinetoolkits | 0 ~ 3.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager connector at /editor/elfinder/php/connector.php without authentication (CVE-2026-34413), because the access-control redirect for unauthenticated users does not call exit()/die() and execution continues server-side. This is chained with a relative path traversal in the elFinder rename command (CVE-2026-34414) and an incomplete file-extension blocklist that still permits .php4 (CVE-2026-34415) to write an attacker-controlled PHP file into the application root, resulting in unauthenticated remote code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-34413.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-34415 | 9.8 CRITICAL | Xerte Online Toolkits File Upload RCE via elfinder Connector |
| CVE-2026-34414 | 7.1 HIGH | Xerte Online Toolkits Path Traversal via connector.php |
| CVE-2026-41459 | 5.3 MEDIUM | Xerte Online Toolkits Path Disclosure via /setup |
No comments yet