- Posts: 6
COMMUNITY FORUM
Security question about elfinder
- rikao
- Topic Author
- Offline
- New Member
Less
More
3 years 8 months ago #178367
by rikao
Security question about elfinder was created by rikao
Hello,
Our security tool detected the following file as malware :
media/k2/assets/vendors/studio-42/elfinder/php/connector.minimal.php-dist
But I confirmed that it is identical to your original file.
So it is not modified.
Currently the file is quarantined (moved to the outside the public folder).
I guess it’s related to the wordpress vulnerability report in the link below:
www.secpod.com/blog/wordpress-file-manager-plugin-under-active-exploitation/
(I don’t know if it also applies to Joomla or not.)
My question is:
Will it be no problem even if the file is removed?
Or
Will it be safe to restore the file?
Thank you for your help, in advance.
Rikao(K2 v2.10.3)
Our security tool detected the following file as malware :
media/k2/assets/vendors/studio-42/elfinder/php/connector.minimal.php-dist
But I confirmed that it is identical to your original file.
So it is not modified.
Currently the file is quarantined (moved to the outside the public folder).
I guess it’s related to the wordpress vulnerability report in the link below:
www.secpod.com/blog/wordpress-file-manager-plugin-under-active-exploitation/
(I don’t know if it also applies to Joomla or not.)
My question is:
Will it be no problem even if the file is removed?
Or
Will it be safe to restore the file?
Thank you for your help, in advance.
Rikao(K2 v2.10.3)
Please Log in or Create an account to join the conversation.
- JoomlaWorks
- Offline
- Admin
Less
More
- Posts: 6218
3 years 7 months ago #178430
by JoomlaWorks
Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)
Replied by JoomlaWorks on topic Security question about elfinder
This file is part of the elFinder distribution (aka the package as downloaded from the relevant GitHub repo) but it's not used by K2 (we have our own connector) nor is it a security risk as it's just a static file (because of the .php-dist extension) for you.
Leaving it or removing it makes no difference. You're safe.
Leaving it or removing it makes no difference. You're safe.
Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)
Please Log in or Create an account to join the conversation.
- rikao
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
3 years 7 months ago #178595
by rikao
Replied by rikao on topic Security question about elfinder
Thank you so much for your reply.
I'm relieved to hear that I can safely remove it.
Thanks for your help.
Best regards,
Rikao
I'm relieved to hear that I can safely remove it.
Thanks for your help.
Best regards,
Rikao
Please Log in or Create an account to join the conversation.
- JoomlaWorks
- Offline
- Admin
Less
More
- Posts: 6218
3 years 7 months ago #178597
by JoomlaWorks
Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)
Replied by JoomlaWorks on topic Security question about elfinder
You're welcome.
Fotis / JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)
Please Log in or Create an account to join the conversation.