Product:

Elfinder

(Std42)
Repositories https://github.com/Studio-42/elFinder
#Vulnerabilities 13
Date Id Summary Products Score Patch Annotated
2024-07-30 CVE-2024-38909 Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc. Elfinder N/A
2023-06-19 CVE-2023-35840 _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector. Elfinder 6.5
2021-06-13 CVE-2021-23394 The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP. Elfinder 9.8