Vulnerability record · CVE-2021-32172 · published 7 October 2021
CVE-2021-32172: Maian Cart Elfinder plugin missing authorization enables pre-auth RCE
Maianscriptworld · Maian Cart
Maian Cart v3.8 contains a broken access control flaw (CWE-862) in the Elfinder plugin that allows remote code execution before authentication. The vulnerability is rated critical with a CVSS 3.1 score of 9.8 and has public exploit code available.
Description
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, public exploit code, and high EPSS probability make this an urgent pre-auth RCE risk.
What it is
Maian Cart v3.8 contains a broken access control flaw (CWE-862) in the Elfinder plugin that allows remote code execution before authentication. The vulnerability is rated critical with a CVSS 3.1 score of 9.8 and has public exploit code available.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of the web application and potentially the underlying host.
Attack surface
The flaw is reachable over the network via the Elfinder plugin endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code exists (referenced in Packet Storm, a blog, and GitHub), and EPSS indicates a high probability of exploitation (0.66433, 99.2nd percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply the latest patch or update from the vendor (maianscriptworld.co.uk) if available.
- If no patch exists, disable or remove the Elfinder plugin from Maian Cart.
- Restrict network access to the Maian Cart administrative and plugin endpoints where possible.
- Monitor for and block exploit attempts targeting the Elfinder plugin using WAF rules.
- Consider replacing Maian Cart v3.8 with a supported version or alternative if the vendor is unresponsive.
Detection
- Monitor web server logs for requests to Elfinder plugin paths with suspicious parameters or file upload attempts.
- Deploy signatures to detect known exploit payloads for CVE-2021-32172.
- Alert on unexpected process creation or outbound connections from the web server host.
- Review file integrity monitoring for unauthorized changes in web-accessible directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164445/Maian-Cart-3.8-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://dreyand.github.io/maian-cart-rce/ | ExploitThird Party Advisory |
| https://github.com/DreyAnd/maian-cart-rce | ExploitThird Party Advisory |
| https://www.maianscriptworld.co.uk/ | Vendor Advisory |
| http://packetstormsecurity.com/files/164445/Maian-Cart-3.8-Remote-Code-Execution.html | ExploitThird Party Advisory |
| https://dreyand.github.io/maian-cart-rce/ | ExploitThird Party Advisory |
| https://github.com/DreyAnd/maian-cart-rce | ExploitThird Party Advisory |
| https://www.maianscriptworld.co.uk/ | Vendor Advisory |
Track CVE-2021-32172 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32172), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.