CVE-2019-5884: STD42 Elfinder

Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.

php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.

Affected products

  • STD42 Elfinder: before 2.1.45 (fixed in 2.1.45)

Published 2019-01-10. Last modified 2026-06-17.