S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32682 Scanner

CVE-2021-32682 scanner - Remote Code Execution (RCE) vulnerability in elFinder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-32682
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
elFinderby Studio-42
= 2.1.58
Updated Aug 19, 2026View on NVD →
Detail

elFinder is an open-source file manager for web, built in JavaScript with jQuery UI. Its purpose is to provide web developers with an efficient tool for managing files across a range of environments. It comes with various file management features, such as file uploading, downloading, editing, and more. As a popular open-source file manager, elFinder has become a top choice for web developers because it is easy to use, customizable and scalable.

Recent research and analysis have uncovered various vulnerabilities in the elFinder 2.1.58 version. The most notable of these is the CVE-2021-32682 vulnerability. This vulnerability allows attackers to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. This can pose a severe threat to businesses that rely on elFinder to manage their files and systems.

An attacker who exploits the CVE-2021-32682 vulnerability can gain full control of the server and can manipulate the files stored there. This could lead to data breaches, ransomware and other malicious activities that compromise the security and integrity of the system. This vulnerability is particularly dangerous because it is easy to exploit and can allow attackers to take over an entire server.

Thanks to the pro features of s4e.io, it is easy for businesses and individuals to learn about vulnerabilities in their digital assets and take steps to protect them. With a comprehensive vulnerability management platform, user can stay updated on the latest vulnerabilities and protect their systems from attacks. For businesses, detecting and eliminating vulnerabilities is essential to ensure the security and continuity of their operations. By emphasizing the importance of proactive cybersecurity measures, we can reduce the risk of falling prey to cyber attacks and keep our digital assets safe and secure.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-32682 vulnerability, a few simple precautions can be taken. These precautions include:

  • Updating elFinder to the latest version (2.1.59), which includes security patches
  • Ensuring the connector is not exposed without authentication
  • Regularly reviewing and monitoring server logs for suspicious activity
  • Enabling firewall rules on the server to block unauthorized access

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-32682 scanner - Remote Code Execution (RCE) vulnerability in elFinder S4E