Studio 42 · Elfinder · CVE-2022-27115
**Name of the Vulnerable Software and Affected Versions**
Studio-42 elFinder version 2.1.60
**Description**
The issue allows for remote code execution through a file name bypass for file upload. This enables an attacker to execute arbitrary code on the server.
**Recommendations**
For Studio-42 elFinder version 2.1.60, at the moment, there is no information about a newer version that contains a fix for this vulnerability.