CVE-2021-32682 is a critical vulnerability affecting elFinder 2.1.58, an open-source web file manager, that allows unauthenticated attackers to execute arbitrary code and commands on the server. With a CVSS score of 9.8 (CRITICAL), this easily exploitable flaw (AV:N/AC:L/PR:N/UI:N) can lead to complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, public exploit modules exist in Metasploit and Nuclei, indicating readily available exploitation tools, despite minimal community discussion or media coverage. Organizations using affected versions should update to 2.1.59 or ensure the connector is not exposed without authentication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.59CPE matchmatch criteria | cpe:2.3:a:std42:elfinder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.