Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13404
HistoryMar 05, 2019 - 8:40 a.m.

OS Command Injection

2019-03-0508:40:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.955

Percentile

99.4%

studio-42/elfinder is vulnerable to OS command injection. Improper processing of the image upload function in the PHP connector allows a remote attacker to inject and execute arbitrary OS commands on the host system.