ZeroHour

CVE-2021-23427

PoC
CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

Vendors
elfinder.netcore project
Products
elfinder.netcore
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.