Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex pattern. Unauthenticated attackers can exploit this flaw combined with authentication bypass and path traversal vulnerabilities to upload malicious PHP code, rename it with a .php4 extension, and execute arbitrary operating system commands on the server.
The elFinder connector endpoint improperly filters uploaded files — an incorrect regex pattern misses the .php4 extension, which is interpreted by the server as executable PHP code. The attacker first exploits an authentication bypass vulnerability, then uses path traversal to place the file in an accessible location. After uploading the file and renaming it to the .php4 extension, remote execution of arbitrary operating system commands on the server (RCE) becomes possible.
An unauthenticated attacker can gain full control over the server by remotely executing arbitrary system commands (RCE), which may lead to data theft, backdoor installation, or further lateral movement in the network.
Apply patches available in the vendor's repository (commits: 02661be88cc369325ea01b508086bde7fbfec805, 17e4f945fe6a3400fa88c01eda18c1075ee4a212, 507d55c5e91bf9310b5b1c7fad8aebfef902ad23) and update the software to a version free of this vulnerability according to vendor references. Until the patch is deployed, consider restricting access to the elFinder endpoint at the firewall or web server level.
Xerte Online Toolkits version 3.15 and earlier
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X