CVE 8.8 HIGH

Xerte Online Toolkits Missing Authentication via connector.php_CVE-2026-34413

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

Description

Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unauthenticated callers does not call exit() or die(), allowing PHP execution to continue and process the full request server-side. Unauthenticated attackers can perform file operations on project media directories including creating directories, uploading files, renaming files, duplicating files, overwriting files, and deleting files, which can be chained with path traversal and extension blocklist vulnerabilities to achieve remote code execution and arbitrary file read.

AI Analysis

Missing authentication vulnerability in Xerte Online Toolkits allowing unauthenticated file operations and potential remote code execution

Basic Information

ID CVE-2026-34413
Source VulnCheck
Published Apr 22, 2026 at 18:33

Affected Product

Vendor thexerteproject
Product xerteonlinetoolkits
Version 3.15.0
Affected Versions thexerteproject xerteonlinetoolkits 3.15.0
thexerteproject xerteonlinetoolkits 3.14.0
thexerteproject xerteonlinetoolkits 3.13.0
thexerteproject xerteonlinetoolkits 0
thexerteproject xerteonlinetoolkits 0
thexerteproject xerteonlinetoolkits 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor The Xerte Project
Product Xerte Online Toolkits
Version 3.15.0, 3.14.0, 3.13.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.