QID 730509
Date Published: 2022-06-06
QID 730509: elFinder File Manager Remote Code Execution (RCE) Vulnerability
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI.
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Affected Versions: elFinder versions 2.1.60
NOTE:
This vulnerability can only be exploited on windows systems.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of elFinder by sending a GET request to elfinder.js file and checking the version banner from it.
Successful exploitation of this vulnerability may allow an remote attacker to execute arbitrary code on the target system.
Solution
Customers are advised to upgrade to elFinder version 2.1.61 or later, for more info check elFinder Security Advisory.
Vendor References
- elFinder Advisory -
github.com/Studio-42/elFinder/issues/3458
CVEs related to QID 730509
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| elFinder Advisory |
|