CVE-2021-32682
Summary
| CVE | CVE-2021-32682 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-14 17:15:00 UTC |
| Updated | 2022-11-09 03:53:00 UTC |
| Description | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication. |
Risk And Classification
Problem Types: CWE-22 | CWE-78 | CWE-918
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple vulnerabilities leading to RCE · Advisory · Studio-42/elFinder · GitHub | CONFIRM | github.com | |
| elFinder Archive Command Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Merge pull request from GHSA-wph3-44rj-92pr · Studio-42/elFinder@a106c35 · GitHub | MISC | github.com | |
| elFinder - A Case Study of Web File Manager Vulnerabilities | MISC | blog.sonarsource.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730183 elFinder File Manager Multiple Vulnerabilites