Record summary

CVE-2021-23394 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus

studio-42/elfinder

CVE ListBefore 2.1.58affected
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 2.1.58 · Fixed in 2.1.58affected

Nuclei templates

1
ProjectDiscoveryHIGHelFinder < 2.1.58 - Remote Code ExecutionCVSS 8.1

studio-42/elfinder before 2.1.58 contains a remote code execution caused by execution of PHP code in a .phar file, letting attackers execute arbitrary PHP code if the server parses .phar files as PHP, exploit requires server to parse .phar files as PHP.

Impact

Attackers can execute arbitrary PHP code on the server, potentially leading to full server compromise.

Remediation

Update to version 2.1.58 or later.

WeaknessesCWE-434
Authors0xanis
Template tagscvecve2021elfinderrcepharfile-uploadintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:*
Shodan: http.title:"elfinder"
FOFA: title="elfinder"
Google: intitle:"elfinder"

Source: ProjectDiscovery

References

7