S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-43421 Scanner

CVE-2021-43421 scanner - File Upload vulnerability in Studio-42 elFinder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-43421
9.8
CVSS

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Studio-42 elFinder is an open-source web-based file manager software that is used for managing files and folders. It is designed to be integrated easily with web applications and can be customized to blend with individual websites. It offers a user-friendly interface and is compatible with all modern web browsers. The software can perform file and folder operations like copying, moving, editing, and deleting. It also provides file upload and download functionality making it easy to store and retrieve files on a server.

Recently, a vulnerability was detected in this popular file manager software, identified as CVE-2021-43421. The vulnerability is found in the connector.minimal.php file allowing remote malicious users to upload arbitrary files and execute PHP code. This vulnerability makes it possible for attackers to gain unauthorized access to a system and compromise the data stored. As a result of the vulnerability, attackers can potentially infect a victims' computer with malware, steal sensitive information and control the affected system.

Exploiting the vulnerability could lead to grave consequences. Cybercriminals can gain control of the server and execute arbitrary code or Trojan commands. The vulnerability in Studio-42 elFinder could be exploited by hackers to bypass authentication and execute arbitrary code resulting in sensitive data theft and cyber espionage. The threat is heightened as this software is very popular with different organizations, including businesses, governments and educational institutions.

By using the pro features of the s4e.io platform, it is possible to quickly and easily identify vulnerabilities in digital assets and take appropriate steps to maintain security. This platform provides vulnerability scanning for web-based applications, database servers, and network devices, with frequent updates that ensure the latest vulnerabilities are always covered. s4e.io also provides a comprehensive vulnerability remediation strategy to ensure that vulnerabilities discovered can be mitigated effectively. Protecting digital assets is no longer just an option, it is a necessity. 

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, the following precautions should be taken:

  • Upgrade elFinder to the latest version
  • Disable any file upload functionality
  • Limit access to the software to authorized persons only
  • Monitor web logs for any suspicious activity
  • Regularly review and audit security policies to ensure they are up-to-date

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-43421 scanner - File Upload vulnerability in Studio-42 elFinder | S4E