Skip to content

Latest commit

 

History

History
9 lines (7 loc) · 545 Bytes

elFinder_RCE.md

File metadata and controls

9 lines (7 loc) · 545 Bytes

elFinder < v2.1.63 - Using .php8 in PHP handler leading to RCE (CVE-2023-52044)

There is no restriction for uploading the file with the .php8 extension. I encountered this situation during penetration testing of a website that uses the elFinder. In some environments, .php8 can be executed as PHP. Especially, when the PHP is updated from a lower version to 8.x, the .php8 can be added to the .htaccess file for PHP handling

PoC

Studio-42/elFinder#3615

Reference

https://nvd.nist.gov/vuln/detail/CVE-2023-52044