CVE-2019-6257: SSRF
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in getremotecontents() in php/elFinder.class.php.
Other sources
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.49 could allow a malicious user to access the content of internal network resources. This occurs in getremotecontents() in php/elFinder.class.php.
— GitHub
Fixed being bypassable of CVE-2019-6257 SSRF.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6257?
CVE-2019-6257 has been classified as a moderate severity vulnerability due to its potential for Server Side Request Forgery (SSRF).
How do I fix CVE-2019-6257?
To fix CVE-2019-6257, update elFinder to version 2.1.49 or later.
What kind of vulnerability is CVE-2019-6257?
CVE-2019-6257 is a Server Side Request Forgery (SSRF) vulnerability.
Which versions of elFinder are affected by CVE-2019-6257?
elFinder versions prior to 2.1.49 are affected by CVE-2019-6257.
What does CVE-2019-6257 allow a malicious user to do?
CVE-2019-6257 allows a malicious user to access the content of internal network resources.