CVE-2023-35840 | elFinder up to 2.1.61 LocalVolumeDriver Connector elFinderVolumeLocalFileSystem.class.php _joinPath path traversal (GHSA-wm5g-p99q-66g4 / EUVD-2023-1903)
A vulnerability was found in elFinder up to 2.1.61. It has been rated as critical. This issue affects the function _joinPath of the file elFinderVolumeLocalFileSystem.class.php of the component LocalVolumeDriver Connector. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2023-35840. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.