Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30957
HistoryJun 14, 2021 - 7:29 a.m.

Unrestricted File Upload

2021-06-1407:29:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
file upload security
php code execution
host os vulnerability
software vulnerability

EPSS

0.023

Percentile

89.9%

studio-42/elfinder allows unrestricted file uploads. An attacker is able to upload PHP code in a .phar file and obtain arbitrary code execution on the host OS.

EPSS

0.023

Percentile

89.9%