CVE-2019-6257: STD42 Elfinder
High severity, CVSS 7.7. EPSS: 1.1% chance of exploitation in the next 30 days.
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.
Affected products
- STD42 Elfinder: before 2.1.46 (fixed in 2.1.46)
Published 2019-01-14. Last modified 2026-06-17.