CVE-2021-23394: Remote Code Execution (RCE)
Published Jun 13, 2021
·Updated
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
Affected Software
1 affected component
std42 elFinder<2.1.58
Remediation
Patch Available
Event History
Jun 13, 2021
CVE Published
via MITRE·11:05 AM
Data Sourced
via MITRE·11:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-23394?
CVE-2021-23394 is rated as a high severity vulnerability due to the risk of Remote Code Execution.
2
How do I fix CVE-2021-23394?
To fix CVE-2021-23394, upgrade elFinder to version 2.1.58 or later, ensuring that the server does not parse .phar files as PHP.
3
What type of vulnerability is CVE-2021-23394?
CVE-2021-23394 is classified as a Remote Code Execution (RCE) vulnerability.
4
Which versions of elFinder are affected by CVE-2021-23394?
CVE-2021-23394 affects all versions of elFinder prior to 2.1.58.
5
What should I do if I cannot upgrade to fix CVE-2021-23394?
If upgrading is not possible, implement strict file type restrictions and conduct thorough security monitoring to mitigate risks associated with CVE-2021-23394.