CVE-2021-23394
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
13/06/2021
Last modified:
09/11/2022
Description
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:* | 2.1.58 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://blog.sonarsource.com/elfinder-case-study-of-web-file-manager-vulnerabilities/
- https://github.com/Studio-42/elFinder
- https://github.com/Studio-42/elFinder/commit/75ea92decc16a5daf7f618f85dc621d1b534b5e1
- https://github.com/Studio-42/elFinder/issues/3295
- https://snyk.io/vuln/SNYK-PHP-STUDIO42ELFINDER-1290554



