CVE-2021-32682: Multiple vulnerabilities leading to RCE
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32682?
CVE-2021-32682 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2021-32682?
To fix CVE-2021-32682, upgrade your elFinder installation to version 2.1.59 or later.
Which versions of elFinder are affected by CVE-2021-32682?
CVE-2021-32682 affects elFinder versions prior to 2.1.59.
What can an attacker do with CVE-2021-32682?
An attacker can execute arbitrary code and commands on the server hosting the elFinder PHP connector.
Is CVS-2021-32682 related to other vulnerabilities?
CVE-2021-32682 is part of a broader set of vulnerabilities identified in elFinder that impact its security posture.