
🚨 CVE-2025-34100: BuilderEngine 3.5... Unauthenticated RCE through elFinder's jQuery upload plugin - drop a PHP shell, own the box in seconds. #RCE #FileUpload #CriticalRCE. https://zerodaysignal.com/vulnerability/CVE-2025-34100 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE-2025-34100, highlighting an unauthenticated RCE in elFinder’s jQuery upload plugin that allows PHP shell upload, and provides a link to a vulnerability page, but gives no evidence of active exploitation, patches, or detailed exploit code.
