elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Github GHSA | 
                GHSA-wph3-44rj-92pr | elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:25:31.074Z
Reserved: 2021-05-12T00:00:00
Link: CVE-2021-32682
No data.
Status : Modified
Published: 2021-06-14T17:15:07.643
Modified: 2024-11-21T06:07:31.390
Link: CVE-2021-32682
No data.
                        OpenCVE Enrichment
                    No data.
 Github GHSA