Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ph33R

#26398of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2022-11833
9.8
2022-04-07
Studio 42 · Elfinder · CVE-2021-43421
**Name of the Vulnerable Software and Affected Versions** Studio-42 elFinder versions 2.0.4 through 2.1.59 **Description** A File Upload issue exists via the `connector.minimal.php` file, allowing a remote malicious user to upload arbitrary files and execute PHP code. **Recommendations** For versions 2.0.4 through 2.1.59, consider disabling the `connector.minimal.php` file as a temporary workaround to prevent exploitation. Restrict access to this file to minimize the risk of uploading and executing malicious PHP code. At the moment, there is no information about a newer version that contains a fix for this issue.