CVE-2019-6257
HIGH7.7EPSS 0.21%elFinder Server Side Request Forgery (SSRF)
Published: 5/13/2022Modified: 2/16/2024
Also known as:GHSA-3qhm-qfj3-4rrx
Description
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.49 could allow a malicious user to access the content of internal network resources. This occurs in `get_remote_contents()` in `php/elFinder.class.php`.
Affected packages (1)
- Packagist/studio-42/elfinderfrom 0, < 2.1.49
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
References (6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-6257
- PATCHhttps://github.com/Studio-42/elFinder
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/studio-42/elfinder/CVE-2019-6257.yaml
- WEBhttps://github.com/Studio-42/elFinder/blob/2.1.49/Changelog
- WEBhttps://github.com/Studio-42/elFinder/commit/2f522db8f037a66ce9040ee0b216aa4a0359286c
- WEBhttps://github.com/Studio-42/elFinder/releases/tag/2.1.49