Elfinder
by Studio 42
Source repositories
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9194 | Cri | 0.67 | 9.8 | 0.97 | Feb 26, 2019 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | ||
| CVE-2023-6825 | Cri | 0.65 | 9.9 | 0.06 | Mar 13, 2024 | The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.… | ||
| CVE-2021-32682 | Cri | 0.65 | 9.8 | 0.70 | Jun 14, 2021 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with… | ||
| CVE-2023-52044 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension. | ||
| CVE-2024-38909 | Cri | 0.64 | 9.8 | 0.00 | Jul 30, 2024 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc. | ||
| CVE-2021-43421 | Cri | 0.60 | 9.8 | 0.43 | Apr 7, 2022 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code. | ||
| CVE-2022-27115 | Cri | 0.59 | 9.8 | 0.29 | Apr 11, 2022 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | ||
| CVE-2019-6257 | Hig | 0.43 | 7.7 | 0.01 | Jan 14, 2019 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php. | ||
| CVE-2023-52045 | Med | 0.40 | 6.1 | 0.00 | Oct 31, 2024 | Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability. | ||
| CVE-2021-45919 | Med | 0.35 | 5.4 | 0.01 | Feb 8, 2022 | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. | ||
| CVE-2019-5884 | Med | 0.31 | 5.9 | 0.01 | Jan 10, 2019 | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. | ||
| CVE-2013-1972 | 0.00 | — | 0.01 | Jun 24, 2013 | Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors. |
- risk 0.67cvss 9.8epss 0.97
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
- risk 0.65cvss 9.9epss 0.06
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.…
- risk 0.65cvss 9.8epss 0.70
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with…
- risk 0.64cvss 9.8epss 0.01
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
- risk 0.64cvss 9.8epss 0.00
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
- risk 0.60cvss 9.8epss 0.43
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
- risk 0.59cvss 9.8epss 0.29
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
- risk 0.43cvss 7.7epss 0.01
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.
- risk 0.40cvss 6.1epss 0.00
Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.
- risk 0.35cvss 5.4epss 0.01
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
- risk 0.31cvss 5.9epss 0.01
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
- CVE-2013-1972Jun 24, 2013risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.