CVE-2021-32682

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-32682
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32682.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32682
Aliases
Published
2021-06-14T17:15:07Z
Modified
2024-05-15T01:14:44.092301Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.

References

Affected packages

Git / github.com/studio-42/elfinder

Affected ranges

Type
GIT
Repo
https://github.com/studio-42/elfinder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.1
1.1

2.*

2.0-beta
2.0-rc1