Home

Description

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler checks the readonly value before performing write operations. The flag only controls client-side UI elements (disabling buttons) and response metadata (write: 0, locked: 1). An attacker who sends requests directly (bypassing the UI) can perform all file operations despite readonly=true. This vulnerability is fixed in 4.08.010.

PUBLISHED Reserved 2026-05-05 | Published 2026-05-12 | Updated 2026-05-13 | Assigner GitHub_M




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-863: Incorrect Authorization

Product status

< 4.08.010
affected

References

github.com/...efw4.X/security/advisories/GHSA-5454-qhrf-vcvh exploit

github.com/...efw4.X/security/advisories/GHSA-5454-qhrf-vcvh

cve.org (CVE-2026-44260)

nvd.nist.gov (CVE-2026-44260)

Download JSON