GHSA-4223-qj94-7x9p
Dashboard / Vulnerabilities / GHSA-4223-qj94-7x9p
Summary: elFinder command injection vulnerability in the PHP connector
Details: elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-9194, https://github.com/Studio-42/elFinder/commit/374c88d7030eb92749267e17a4af21cc7520efa5, https://github.com/FriendsOfPHP/security-advisories/blob/master/studio-42/elfinder/CVE-2019-9194.yaml, https://github.com/Studio-42/elFinder, https://github.com/Studio-42/elFinder/blob/master/README.md, https://github.com/Studio-42/elFinder/compare/6884c4f...0740028, https://github.com/Studio-42/elFinder/releases/tag/2.1.48, https://www.exploit-db.com/exploits/46481, https://www.exploit-db.com/exploits/46539
Affected packages
Package
Name: studio-42/elfinder
Purl: pkg:composer/studio-42/elfinder
Affected ranges
Type: ECOSYSTEM
Events:
