CVE-2019-9194: Command Injection
Published Feb 26, 2019
·Updated
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Affected Software
3 affected componentsFixes available
composer/studio-42/elfinder<2.1.48
2.1.48
composer/studio-42/elfinder<2.1.48
2.1.48
std42 elFinder<2.1.48
Remediation
Event History
Feb 26, 2019
Advisory Published
12:10 PM
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9194?
CVE-2019-9194 is classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2019-9194?
To mitigate CVE-2019-9194, upgrade elFinder to version 2.1.48 or later.
3
What versions of elFinder are affected by CVE-2019-9194?
Versions of elFinder prior to 2.1.48 are affected by CVE-2019-9194.
4
What type of vulnerability is CVE-2019-9194?
CVE-2019-9194 is a command injection vulnerability in the PHP connector of elFinder.
5
Who is the vendor associated with CVE-2019-9194?
The vendor associated with CVE-2019-9194 is Studio-42, the maintainers of elFinder.