logo

Database

Insecure file upload In studio-42/elfinder

Description

RCE in Studio-42 elFinder on Windows before 2.1.61 In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions