← voltar
CVE-2021-32682criticalCWE-22CWE-78CWE-918

Multiple vulnerabilities leading to RCE

75Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 9.8epss 70%
da publicação à arma0 dias
Publicada no NVD14 de jun.
metasploit13 de jun.
probabilidade de exploração
70%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Studio-42 · elFinder
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.