Junglewise Threat Intelligence

CVE-2026-44258: efwGrp efw4.X path traversal in elfinder_paste

CVE-2026-44258 · Severity: info · CVSS 9.3 · Published 2026-05-12

Technologies: efwGrp efw4.X.

Executive brief

efw4.X is an enterprise web development framework. A security flaw in its file management component allows an attacker to move or copy files to unauthorized locations on the server. This can be used to plant malicious scripts (webshells) in web directories, leading to a complete takeover of the server and access to sensitive data.

Technical details

A path traversal vulnerability exists in the elfinder_paste functionality of efw4.X. While the elfinder_checkRisk function validates the 'target' and 'targets' parameters for path traversal and home directory containment, it fails to inspect the 'dst' (destination) parameter. An attacker can provide a base64-encoded traversal path (e.g., '../../..') in the 'dst' parameter to copy or move files from the restricted home directory to arbitrary locations on the filesystem. By staging a JSP webshell in the home directory and using this flaw to copy it to the web application root, an unauthenticated attacker can achieve Remote Code Execution (RCE). This vulnerability is fixed in version 4.08.010.

Affected products

  • efwGrp efw4.X < 4.08.010

Timeline

  • 2026-04-28: advisory: GitHub Security Advisory published
  • 2026-05-12: disclosed: CVE published to NVD

References