Studio-42 elFinder 2.0.4 to 2.1.59 is vulnerable to unauthenticated file upload via connector.minimal.php which could allow a remote user to upload arbitrary files and execute PHP code.
View the template here CVE-2021-43421.yaml
References:
https://github.com/ARPSyndicate/kenzer-templates