GHSA-3qhm-qfj3-4rrx
Dashboard / Vulnerabilities / GHSA-3qhm-qfj3-4rrx
Summary: elFinder Server Side Request Forgery (SSRF)
Details: A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.49 could allow a malicious user to access the content of internal network resources. This occurs in `get_remote_contents()` in `php/elFinder.class.php`.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-6257, https://github.com/Studio-42/elFinder/commit/2f522db8f037a66ce9040ee0b216aa4a0359286c, https://github.com/FriendsOfPHP/security-advisories/blob/master/studio-42/elfinder/CVE-2019-6257.yaml, https://github.com/Studio-42/elFinder, https://github.com/Studio-42/elFinder/blob/2.1.49/Changelog, https://github.com/Studio-42/elFinder/releases/tag/2.1.49
Affected packages
Package
Name: studio-42/elfinder
Purl: pkg:composer/studio-42/elfinder
Affected ranges
Type: ECOSYSTEM
Events:
