CVE-2021-43421 Scanner

Detects 'File Upload' vulnerability in Studio-42 elFinder affects v. 2.0.4 to 2.1.59.


CVE-2021-43421 Scanner Detail

Studio-42 elFinder is an open-source web-based file manager software that is used for managing files and folders. It is designed to be integrated easily with web applications and can be customized to blend with individual websites. It offers a user-friendly interface and is compatible with all modern web browsers. The software can perform file and folder operations like copying, moving, editing, and deleting. It also provides file upload and download functionality making it easy to store and retrieve files on a server.

Recently, a vulnerability was detected in this popular file manager software, identified as CVE-2021-43421. The vulnerability is found in the connector.minimal.php file allowing remote malicious users to upload arbitrary files and execute PHP code. This vulnerability makes it possible for attackers to gain unauthorized access to a system and compromise the data stored. As a result of the vulnerability, attackers can potentially infect a victims' computer with malware, steal sensitive information and control the affected system.

Exploiting the vulnerability could lead to grave consequences. Cybercriminals can gain control of the server and execute arbitrary code or Trojan commands. The vulnerability in Studio-42 elFinder could be exploited by hackers to bypass authentication and execute arbitrary code resulting in sensitive data theft and cyber espionage. The threat is heightened as this software is very popular with different organizations, including businesses, governments and educational institutions.

