9.8
/ 10
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2019-9194 — elFinder Command Injection PoC Command injection vulnerability in elFinder = 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user. How it works Uploads a valid JPEG with a malicious...
Basic Information
ID
709F1CDB-2F66-54FD-B9A8-C133DF650F13
Published
Feb 18, 2026 at 00:40
Modified
Feb 18, 2026 at 03:08