CVE detail
CVE-2021-23394 — CVE-2021-23394
Published 2021-06-13 · Modified 2026-06-17 · Vendor std42 · Product elfinder · Source nvd
HIGH
severity
CVSS-derived band
0.1908
EPSS probability
exploitation probability, 30d
97.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References