CVE-2021-43421
elFinder Unrestricted File Upload vulnerability
Record summary
CVE-2021-43421 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
studio-42/elfinderBrowse Packagist / studio-42/elfinder | GitHub Advisory | 2.0.4 to < 2.1.60 · Fixed in 2.1.60 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALStudio-42 elFinder <2.1.60 - Arbitrary File UploadCVSS 9.8
Studio-42 elFinder 2.0.4 to 2.1.59 is vulnerable to unauthenticated file upload via connector.minimal.php which could allow a remote user to upload arbitrary files and execute PHP code.
Impact
Successful exploitation of this vulnerability could allow an attacker to upload malicious files to the server and execute arbitrary code.
Remediation
Upgrade to the latest version of Studio-42 elFinder plugin (2.1.60 or higher) to mitigate this vulnerability.
Source: ProjectDiscovery