Record summary

CVE-2021-43421 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory2.0.4 to < 2.1.60 · Fixed in 2.1.60affected

Nuclei templates

1
ProjectDiscoveryCRITICALStudio-42 elFinder <2.1.60 - Arbitrary File UploadCVSS 9.8

Studio-42 elFinder 2.0.4 to 2.1.59 is vulnerable to unauthenticated file upload via connector.minimal.php which could allow a remote user to upload arbitrary files and execute PHP code.

Impact

Successful exploitation of this vulnerability could allow an attacker to upload malicious files to the server and execute arbitrary code.

Remediation

Upgrade to the latest version of Studio-42 elFinder plugin (2.1.60 or higher) to mitigate this vulnerability.

WeaknessesCWE-434
Authorsakincibor
Template tagscvecve2021elfinderfileuploadrceintrusivestd42vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5