Xerte Online Toolkits是英国Xerte公司的一个在线学习内容制作平台。 Xerte Online Toolkits 3.15及之前版本存在安全漏洞,该漏洞源于未经验证的用户可访问/setup页面获取应用程序根目录的完整服务器端文件系统路径,可能导致信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| thexerteproject | xerteonlinetoolkits | 3.15.0 |
affected |
< f063e942b4a9bf77a06829e844c2c70316bc45e8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thexerteproject | xerteonlinetoolkits | 3.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34415 | 9.8 CRITICAL | Xerte Online Toolkits File Upload RCE via elfinder Connector |
| CVE-2026-34413 | 8.6 HIGH | Xerte Online Toolkits Missing Authentication via connector.php |
| CVE-2026-34414 | 7.1 HIGH | Xerte Online Toolkits Path Traversal via connector.php |
No comments yet