Lucene search

K
osvGoogleOSV:GHSA-X4JX-HJWF-GC99
HistoryApr 08, 2022 - 12:00 a.m.

elFinder Unrestricted File Upload vulnerability

2022-04-0800:00:23
Google
osv.dev
6
file upload
elfinder
studio-42
remote
arbitrary files
php code
vulnerability

AI Score

9.6

Confidence

High

EPSS

0.066

Percentile

93.8%

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

AI Score

9.6

Confidence

High

EPSS

0.066

Percentile

93.8%

Related for OSV:GHSA-X4JX-HJWF-GC99