{"id":"CVE-2019-5884","aliases":["GHSA-jcgc-vxqg-85xx"],"url":"https://o3.security/vulnerability/CVE-2019-5884","summary":"Sensitive Data Exposure in elFinder","details":"php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.","published":"2019-01-10T08:29:00.263Z","modified":"2026-08-07T16:35:24.872305Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01275,"percentile":0.67239,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"studio-42/elfinder","fixedVersion":"2.1.45"}],"fix":{"url":"https://github.com/Studio-42/elFinder/commit/f133163f2d754584de65d718b2fde96191557316","label":"Studio-42/elFinder@f133163"},"references":[{"type":"ADVISORY","url":"https://github.com/Studio-42/elFinder/releases/tag/2.1.45"},{"type":"FIX","url":"https://github.com/Studio-42/elFinder/commit/f133163f2d754584de65d718b2fde96191557316"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:24.872305Z"}}