# Title: ckeditor-elfinder Remote File Upload Vulnerability
# Author: h4shur
# date: 2020-09-22
# Vendor Homepage: https://github.com/bayucandra/ckeditor-elfinder
# Tested on: Windows 10 & Google Chrome
# Category : Web Application Bugs
# Dork : inurl:"/vendor/elFinder/elfinder.html"
### NOTE:
* You can bypass it to upload your shell or deface.
*
### POC:
* Exploit 1 : site.com/vendor/elFinder/elfinder.html
### Directory File Path :
* site.com/[folders]/[FILE]
### Contact Me :
* Email : h4shursec@gmail.com
* twitter : t.co/h4shur
* facebook : fb.me/h4shur
* Telegram : t.me/h4shur
* Instagram : ig.me/netedit0r