blog.sonarsource.com
https://blog.sonarsource.com/elfinder-case-study-of-web-file-manager-vulnerabilities CVE-2021-23394
HIGHNuclei
Remote Code Execution (RCE)
Record summary
CVE-2021-23394 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.
Description
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
studio-42/elfinder | CVE List | Before 2.1.58 | affected |
elfinderBrowse std42 / elfinder | VulnCheck | Version data not supplied | |
studio-42/elfinderBrowse Packagist / studio-42/elfinder | GitHub Advisory | Before 2.1.58 · Fixed in 2.1.58 | affected |
Nuclei templates
1ProjectDiscoveryHIGHelFinder < 2.1.58 - Remote Code ExecutionCVSS 8.1
studio-42/elfinder before 2.1.58 contains a remote code execution caused by execution of PHP code in a .phar file, letting attackers execute arbitrary PHP code if the server parses .phar files as PHP, exploit requires server to parse .phar files as PHP.
Impact
Attackers can execute arbitrary PHP code on the server, potentially leading to full server compromise.
Remediation
Update to version 2.1.58 or later.
WeaknessesCWE-434
Authors0xanis
Template tagscvecve2021elfinderrcepharfile-uploadintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:*
Shodan: http.title:"elfinder"
FOFA: title="elfinder"
Google: intitle:"elfinder"
https://github.com/Studio-42/elFinder/issues/3295 https://blog.sonarsource.com/elfinder-the-story-of-a-file-manager-and-a-bunch-of-vulnerabilities https://snyk.io/vuln/SNYK-PHP-STUDIO42ELFINDER-1290554 https://nvd.nist.gov/vuln/detail/CVE-2021-23394
Source: ProjectDiscovery
References
7github.com
https://github.com/Studio-42/elFinder github.com
https://github.com/Studio-42/elFinder/commit/75ea92decc16a5daf7f618f85dc621d1b534b5e1 github.com
https://github.com/Studio-42/elFinder/issues/3295 github.com
https://github.com/Studio-42/elFinder/security/advisories/GHSA-qm58-cvvm-c5qr nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-23394 snyk.io
https://snyk.io/vuln/SNYK-PHP-STUDIO42ELFINDER-1290554