CVE-2021-43421: Malicious File Upload
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
Other sources
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43421?
CVE-2021-43421 is classified as a high severity vulnerability due to its ability to allow remote code execution via arbitrary file uploads.
How do I fix CVE-2021-43421?
To address CVE-2021-43421, upgrade your elFinder to version 2.1.60 or later.
What software is affected by CVE-2021-43421?
CVE-2021-43421 affects Studio-42 elFinder versions 2.0.4 to 2.1.59.
Can CVE-2021-43421 lead to a data breach?
Yes, CVE-2021-43421 can lead to a data breach as it allows remote users to execute malicious PHP code.
What file types can be uploaded through CVE-2021-43421?
CVE-2021-43421 allows a remote user to upload arbitrary files, potentially including malicious script files.