Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-34413— Xerte Online Toolkits Missing Authentication via connector.php

Quick assessment

Affected
thexerteproject xerteonlinetoolkits
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Xerte Online Toolkits是英国Xerte公司的一个在线学习内容制作平台。 Xerte Online Toolkits 3.15及之前版本存在安全漏洞,该漏洞源于/editor/elfinder/php/connector.php端点的elFinder连接器缺少身份验证,HTTP重定向未调用exit或die,导致PHP继续执行完整请求,未经身份验证的攻击者可对项目媒体目录执行文件操作,包括创建目录、上传文件、重命名文件、复制文件、覆盖文件和删除文件,结合路径遍历和扩展阻止列表漏洞可能导致远

CVSS 8.6 · High EPSS 3.07% · P87

Affected Version Matrix 1

VendorProduct Version RangeStatus
thexerteproject xerteonlinetoolkits ≤ 3.15.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-34413

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Xerte Online Toolkits Missing Authentication via connector.php
Source: CVE Program / CVE List V5
Vulnerability Description
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
将系统数据暴露到未授权控制的范围
Source: CVE Program / CVE List V5
Vulnerability Title
Xerte Online Toolkits 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Xerte Online Toolkits是英国Xerte公司的一个在线学习内容制作平台。 Xerte Online Toolkits 3.15及之前版本存在安全漏洞,该漏洞源于/editor/elfinder/php/connector.php端点的elFinder连接器缺少身份验证,HTTP重定向未调用exit或die,导致PHP继续执行完整请求,未经身份验证的攻击者可对项目媒体目录执行文件操作,包括创建目录、上传文件、重命名文件、复制文件、覆盖文件和删除文件,结合路径遍历和扩展阻止列表漏洞可能导致远
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
thexerteproject xerteonlinetoolkits 0 ~ 3.15.0 -

II. Public POCs for CVE-2026-34413

# POC Description Source Link Shenlong Link
1 Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager connector at /editor/elfinder/php/connector.php without authentication (CVE-2026-34413), because the access-control redirect for unauthenticated users does not call exit()/die() and execution continues server-side. This is chained with a relative path traversal in the elFinder rename command (CVE-2026-34414) and an incomplete file-extension blocklist that still permits .php4 (CVE-2026-34415) to write an attacker-controlled PHP file into the application root, resulting in unauthenticated remote code execution. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-34413.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-34413

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-34413 (3)

Exploits & Public PoCs for CVE-2026-34413 (1)

Other References for CVE-2026-34413 (1)

Other References for CVE-2026-34413 (1)

Same Patch Batch · thexerteproject · 2026-04-22 · 4 CVEs total

CVE-2026-34415 9.8 CRITICAL Xerte Online Toolkits File Upload RCE via elfinder Connector
CVE-2026-34414 7.1 HIGH Xerte Online Toolkits Path Traversal via connector.php
CVE-2026-41459 5.3 MEDIUM Xerte Online Toolkits Path Disclosure via /setup

IV. Related Vulnerabilities

V. Comments for CVE-2026-34413

No comments yet


Leave a comment