elFinder Unrestricted File Upload vulnerability
Critical severity
GitHub Reviewed
Published
Apr 8, 2022
to the GitHub Advisory Database
•
Updated Jan 10, 2024
Description
Published by the National Vulnerability Database
Apr 7, 2022
Published to the GitHub Advisory Database
Apr 8, 2022
Reviewed
Jan 10, 2024
Last updated
Jan 10, 2024
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via
connector.minimal.php
, which allows a remote malicious user to upload arbitrary files and execute PHP code.References