CVE-2023-52044
- EPSS 1.32%
- Veröffentlicht 31.10.2024 19:15:12
- Zuletzt bearbeitet 17.04.2025 19:11:53
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
CVE-2023-52045
- EPSS 0.09%
- Veröffentlicht 31.10.2024 19:15:12
- Zuletzt bearbeitet 17.04.2025 19:11:05
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
CVE-2024-38909
- EPSS 0.19%
- Veröffentlicht 30.07.2024 14:15:02
- Zuletzt bearbeitet 28.04.2025 14:35:52
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVE-2023-35840
- EPSS 5.22%
- Veröffentlicht 19.06.2023 01:15:08
- Zuletzt bearbeitet 12.12.2024 01:24:18
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
CVE-2022-27115
- EPSS 14.78%
- Veröffentlicht 11.04.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:10
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
CVE-2021-43421
- EPSS 76.57%
- Veröffentlicht 07.04.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:12
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
CVE-2022-26960
- EPSS 86.39%
- Veröffentlicht 21.03.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:52
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to improper handling of absolute fil...
CVE-2021-45919
- EPSS 0.35%
- Veröffentlicht 08.02.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:16
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
CVE-2021-32682
- EPSS 93.53%
- Veröffentlicht 14.06.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:31
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFin...
CVE-2021-23394
- EPSS 3.2%
- Veröffentlicht 13.06.2021 11:15:14
- Zuletzt bearbeitet 21.11.2024 05:51:38
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.