elfinder-version: elFinder 2.1.58 - Remote Code Execution

2025-08-01 elFinder PoC Public

Description

elFinder 2.1.58 is vulnerable to remote code execution. This can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration.

PoC

id: elfinder-version

info:
  name: elFinder 2.1.58 - Remote Code Execution
  author: idealphase
  severity: critical
  description: elFinder 2.1.58 is vulnerable to remote code execution. This can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration.
  remediation: The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication.
  reference:
    - https://github.com/Studio-42/elFinder/
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    cvss-score: 10
    cwe-id: CWE-78
  metadata:
    max-request: 2
  tags: tech,elfinder,oss,discovery

http:
  - method: GET
    path:
      - "{{BaseURL}}/js/elfinder.min.js"
      - "{{BaseURL}}/js/elFinder.version.js"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "elFinder - file manager for web"
          - "elFinder.prototype.version ="
        condition: or

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        group: 1
        regex:
          - '\* Version (.+) \('
          - "elFinder.prototype.version = '([0-9.]+)';"
# digest: 4b0a00483046022100c43eb224ad49f6a8516d0399576858fb7001c4a50e02b5f86138d6f09e05921d022100809f686639e2945afb9bfcb2ca6415b9e7db7a7e5ba37fd2dd4617b345ea30e3:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities