No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Efwgrp
Efwgrp efw4.x |
|
| Vendors & Products |
Efwgrp
Efwgrp efw4.x |
Tue, 12 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When protected=true, elfinder_checkRisk enforces that the client sends readonly=true (matching the session value), but no event handler checks the readonly value before performing write operations. The flag only controls client-side UI elements (disabling buttons) and response metadata (write: 0, locked: 1). An attacker who sends requests directly (bypassing the UI) can perform all file operations despite readonly=true. This vulnerability is fixed in 4.08.010. | |
| Title | efw4.X: readonly Flag Not Enforced Server-Side | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T15:37:13.906Z
Reserved: 2026-05-05T16:33:55.844Z
Link: CVE-2026-44260
Updated: 2026-05-13T15:04:06.660Z
Status : Deferred
Published: 2026-05-12T22:16:36.417
Modified: 2026-05-13T16:16:55.437
Link: CVE-2026-44260
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:35:28Z