Lucene search

K
osvGoogleOSV:CVE-2021-23394
HistoryJun 13, 2021 - 11:15 a.m.

CVE-2021-23394

2021-06-1311:15:14
Google
osv.dev
9
cve-2021-23394
remote code execution
php parsing
software

AI Score

7.6

Confidence

High

EPSS

0.023

Percentile

89.9%

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.

AI Score

7.6

Confidence

High

EPSS

0.023

Percentile

89.9%