CVE-2026-34414 Details
Description
Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in rename commands is not sanitized for path traversal sequences. Attackers can supply a name value containing directory traversal sequences to move files from project media directories to arbitrary locations on the filesystem, potentially overwriting application files, achieving stored cross-site scripting, or combining with other vulnerabilities to achieve unauthenticated remote code execution by moving PHP code files to the application root.
A relative path traversal vulnerability has been identified in Xerte Online Toolkits versions 3.15 and earlier. The issue resides in the elFinder connector endpoint, specifically in the file '/editor/elfinder/php/connector.php'. The vulnerability arises because the 'name' parameter in rename commands is not properly sanitized, allowing attackers to inject directory traversal sequences. This exploitation could lead to moving files from project media directories to arbitrary locations on the filesystem. Such actions might overwrite application files, introduce stored cross-site scripting, or, when combined with other vulnerabilities, enable unauthenticated remote code execution by relocating PHP code files to the application root.
Users are advised to update to Xerte Online Toolkits version 3.15.0 or later, and to run the upgrade.php script after updating. For versions 3.14 and 3.13, similar update procedures apply.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2026CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Xerte Online Toolkits | <= 3.15.0 (semver) <= 3.14.0 (semver) <= 3.13.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | New CVE Received | [email protected] |
Volerion