9.8

CVE-2021-23394

Exploit

Remote Code Execution (RCE)

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Std42Elfinder Version < 2.1.58
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.08% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
report@snyk.io 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://blog.sonarsource.com/elfinder-case-study-of-web-file-manager-vulnerabilities/
Third Party Advisory
Exploit
https://github.com/Studio-42/elFinder
Third Party Advisory
https://github.com/Studio-42/elFinder/commit/75ea92decc16a5daf7f618f85dc621d1b534b5e1
Patch
Third Party Advisory
https://github.com/Studio-42/elFinder/issues/3295
Patch
Third Party Advisory
Exploit
Issue Tracking
https://snyk.io/vuln/SNYK-PHP-STUDIO42ELFINDER-1290554
Third Party Advisory