CVE-2022-27115 is a critical remote code execution vulnerability (CVSS 9.8) affecting Studio-42 elFinder versions 2.1.60 and earlier, including its Microsoft Windows implementations. This flaw allows unauthenticated attackers to execute arbitrary code by bypassing file upload restrictions. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the high severity and ease of exploitation (AV:N/AC:L/PR:N/UI:N) warrant immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.60CPE matchmatch criteria | cpe:2.3:a:std42:elfinder:2.1.60:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.