CVE-2021-23427
Arbitrary File Write via Archive Extraction (Zip Slip)
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L/E:F/RL:U/RC:C
Affected products
n/a · elFinder.NetCoreWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →