vendor:
elFinder
by:
tmrswrr
6.1
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: elFinder
Affected Version From: 2.1.53
Affected Version To: 2.1.53
Patch Exists: NO
Related CWE:
CPE: a:studio-42:elfinder:2.1.53
Platforms Tested:
2023
elFinder Web file manager Version: 2.1.53 Remote Command Execution
The elFinder Web file manager version 2.1.53 allows remote attackers to execute arbitrary commands via uploading a crafted PHP file that leverages the system function.
Mitigation:
Avoid allowing file uploads from untrusted sources, and implement proper input validation to prevent command execution.