OVERVIEW Xerte Online Toolkits versions 3.15 and earlier contain a critical authentication bypass vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php. The flaw exists because HTTP redirects to unauthenticated users fail to terminate PHP execution, allowing requests to continue processing server-side. This permits unauthenticated attackers to perform unauthorized file operations including uploading, creating, renaming, deleting, and overwriting files in project media directories. SEVERITY The vulnerability carries a CVSS score of 8.6 (HIGH) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, indicating exploitation is straightforward. The impact is significant: attackers can manipulate files on the server, and when chained with path traversal and extension blocklist bypass vulnerabilities, achieve remote code execution and read arbitrary files. The FAUCET Risk Score of 51.0/100 reflects elevated concern within the security community. EXPLOITATION STATUS The vulnerability is currently active on threat tracking lists and warrants immediate attention, though it does not appear in the Known Exploited Vulnerabilities catalog. The relatively low EPSS score of 0.003 suggests limited current exploitation in the wild compared to other CVEs. However, the straightforward nature of the authentication bypass and high potential impact make this a priority for patching, particularly for organizations running affected Xerte versions in internet-facing environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Thexerteproject | Xerteonlinetoolkits | >= 0, <= 3.15.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.