CVE-2019-5884: Infoleak
Published Jan 10, 2019
·Updated
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safemode or openbasedir is not set.
Affected Software
1 affected component
std42 elFinder<2.1.45
Remediation
Event History
Jan 10, 2019
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·08:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5884?
CVE-2019-5884 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-5884?
To fix CVE-2019-5884, upgrade elFinder to version 2.1.45 or later.
3
What information does CVE-2019-5884 leak?
CVE-2019-5884 can leak sensitive information when PHP's curl extension is enabled without safe_mode or open_basedir restrictions.
4
Which versions of elFinder are affected by CVE-2019-5884?
elFinder versions earlier than 2.1.45 are affected by CVE-2019-5884.
5
What conditions exacerbate CVE-2019-5884?
CVE-2019-5884 is exacerbated when PHP's curl extension is enabled and safe_mode or open_basedir is not configured.