CVE-2019-6257

HIGH7.7EPSS 0.21%

elFinder Server Side Request Forgery (SSRF)

Published: 5/13/2022Modified: 2/16/2024
Also known as:GHSA-3qhm-qfj3-4rrx

Description

A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.49 could allow a malicious user to access the content of internal network resources. This occurs in `get_remote_contents()` in `php/elFinder.class.php`.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

References (6)