İçeriğe atla
Noroxi

std42 kayıtları

std42 üreticisine ait 16 yayımlanmış kayıt.

Tüm kayıtlar

16 kayıt
  • CVE-2019-9194
    68Bu hafta

    elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

    KritikCVSS 9,8SilahlaştırılmışEPSS %97

    std42 · elfinder26 Şub 2019

  • CVE-2021-32682
    60Bu hafta

    Multiple vulnerabilities leading to RCE

    KritikCVSS 9,8SilahlaştırılmışEPSS %70

    std42 · elfinder14 Haz 2021

  • CVE-2021-43421
    52Planlayın

    A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to

    KritikCVSS 9,8Kavram kanıtıEPSS %43

    std42 · elfinder7 Nis 2022

  • CVE-2022-26960
    51Planlayın

    connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal.

    KritikCVSS 9,1Kavram kanıtıEPSS %51

    std42 · elfinder21 Mar 2022

  • CVE-2022-27115
    48Planlayın

    In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

    KritikCVSS 9,8İstismar yokEPSS %29

    std42 · elfinder11 Nis 2022

  • CVE-2021-23394
    45Planlayın

    Remote Code Execution (RCE)

    KritikCVSS 9,8Kavram kanıtıEPSS %19

    std42 · elfinder13 Haz 2021

  • CVE-2023-52044
    39İzleyin

    Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extensi

    KritikCVSS 9,8İstismar yokEPSS %1

    std42 · elfinder31 Eki 2024

  • CVE-2024-38909
    39İzleyin

    Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control.

    KritikCVSS 9,8İstismar yokEPSS %0

    std42 · elfinder30 Tem 2024

  • CVE-2018-9109
    37İzleyin

    Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re

    KritikCVSS 9,1İstismar yokEPSS %3

    std42 · elfinder28 Mar 2018

  • CVE-2018-9110
    37İzleyin

    Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a re

    KritikCVSS 9,1İstismar yokEPSS %3

    std42 · elfinder28 Mar 2018

  • CVE-2026-41247
    36İzleyin

    elFinder: Command injection in resize background color parameter when using ImageMagick CLI

    YüksekCVSS 8,9İstismar yokEPSS %3

    std42 · elfinder23 Nis 2026

  • CVE-2019-6257
    30İzleyin

    A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal

    YüksekCVSS 7,7İstismar yokEPSS %1

    std42 · elfinder14 Oca 2019

  • CVE-2023-35840
    27İzleyin

    _joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

    OrtaCVSS 6,5Kavram kanıtıEPSS %2

    std42 · elfinder18 Haz 2023

  • CVE-2023-52045
    24İzleyin

    Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %0

    std42 · elfinder31 Eki 2024

  • CVE-2019-5884
    23İzleyin

    php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not s

    OrtaCVSS 5,9İstismar yokEPSS %1

    std42 · elfinder10 Oca 2019

  • CVE-2021-45919
    21İzleyin

    Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.

    OrtaCVSS 5,4İstismar yokEPSS %1

    std42 · elfinder8 Şub 2022