CVE-2018-9109: Path Traversal
(updated )
Studio elFinder has a directory traversal vulnerability in elFinder.class.php
with the zipdl()
function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
References
Detect and mitigate CVE-2018-9109 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →