Skip to content
Noroxi

std42 records

16 published records for vendor std42.

All records

16 records
  • CVE-2019-9194
    68This week

    elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

    CriticalCVSS 9.8WeaponizedEPSS 97%

    std42 · elfinderFeb 26, 2019

  • CVE-2021-32682
    60This week

    Multiple vulnerabilities leading to RCE

    CriticalCVSS 9.8WeaponizedEPSS 70%

    std42 · elfinderJun 14, 2021

  • A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to

    CriticalCVSS 9.8Proof of conceptEPSS 43%

    std42 · elfinderApr 7, 2022

  • connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.

    CriticalCVSS 9.1Proof of conceptEPSS 51%

    std42 · elfinderMar 21, 2022

  • In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

    CriticalCVSS 9.8No exploitEPSS 29%

    std42 · elfinderApr 11, 2022

  • Remote Code Execution (RCE)

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    std42 · elfinderJun 13, 2021

  • Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensi

    CriticalCVSS 9.8No exploitEPSS 1%

    std42 · elfinderOct 31, 2024

  • Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.

    CriticalCVSS 9.8No exploitEPSS 0%

    std42 · elfinderJul 30, 2024

  • CVE-2018-9109
    37Monitor

    Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re

    CriticalCVSS 9.1No exploitEPSS 3%

    std42 · elfinderMar 28, 2018

  • CVE-2018-9110
    37Monitor

    Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re

    CriticalCVSS 9.1No exploitEPSS 3%

    std42 · elfinderMar 28, 2018

  • elFinder: Command injection in resize background color parameter when using ImageMagick CLI

    HighCVSS 8.9No exploitEPSS 3%

    std42 · elfinderApr 23, 2026

  • CVE-2019-6257
    30Monitor

    A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal

    HighCVSS 7.7No exploitEPSS 1%

    std42 · elfinderJan 14, 2019

  • _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

    MediumCVSS 6.5Proof of conceptEPSS 2%

    std42 · elfinderJun 18, 2023

  • Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

    MediumCVSS 6.1No exploitEPSS 0%

    std42 · elfinderOct 31, 2024

  • CVE-2019-5884
    23Monitor

    php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not s

    MediumCVSS 5.9No exploitEPSS 1%

    std42 · elfinderJan 10, 2019

  • Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

    MediumCVSS 5.4No exploitEPSS 1%

    std42 · elfinderFeb 8, 2022