漏洞描述
Xerte Online Toolkits versions 3.15 and earlier expose the elFinder file manager connector at /editor/elfinder/php/connector.php without authentication (CVE-2026-34413), because the access-control redirect for unauthenticated users does not call exit()/die() and execution continues server-side. This is chained with a relative path traversal in the elFinder rename command (CVE-2026-34414) and an incomplete file-extension blocklist that still permits .php4 (CVE-2026-34415) to write an attacker-controlled PHP file into the application root, resulting in unauthenticated remote code execution.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.vulncheck.comhttps://www.vulncheck.com/advisories/xerte-online-toolkits-missing-authentication-via-connector-php↗github.comhttps://github.com/bootstrapbool/xerteonlinetoolkits-rce↗github.comhttps://github.com/thexerteproject/xerteonlinetoolkits/issues/1527↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34413↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34414↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34415↗