
CVE-2026-44260 efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is intended to prevent file modifications. When prot… https://www.cve.org/CVERecord?id=CVE-2026-44260
Post summary
The post discloses that versions of efw4.X prior to 4.08.010 have a flaw in the readonly flag of the JSP tag which could allow file modifications.

