CVE-2022-27115: Malicious File Upload
Published Apr 11, 2022
·Updated
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Affected Software
2 affected components
std42 elFinder=2.1.60
Microsoft Windows
Remediation
Patch Available
Event History
Apr 11, 2022
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27115?
CVE-2022-27115 is rated as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2022-27115?
To fix CVE-2022-27115, upgrade to elFinder version 2.1.61 or later which addresses the file upload vulnerability.
3
What software is affected by CVE-2022-27115?
CVE-2022-27115 specifically affects Studio-42 elFinder version 2.1.60.
4
What type of vulnerability is CVE-2022-27115?
CVE-2022-27115 is a remote code execution vulnerability caused by file name bypass during file uploads.
5
Can CVE-2022-27115 impact my system if I am using a patched version?
If you are using a patched version of elFinder, your system is not at risk from CVE-2022-27115.