{"id":"CVE-2019-6257","aliases":["GHSA-3qhm-qfj3-4rrx"],"url":"https://o3.security/vulnerability/CVE-2019-6257","summary":"elFinder Server Side Request Forgery (SSRF)","details":"A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.","published":"2019-01-14T08:29:00.473Z","modified":"2026-08-07T16:35:25.406288Z","cvss":{"score":7.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"},"epss":{"score":0.01098,"percentile":0.63961,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"studio-42/elfinder","fixedVersion":"2.1.49"}],"fix":{"url":"https://github.com/Studio-42/elFinder/commit/2f522db8f037a66ce9040ee0b216aa4a0359286c","label":"Studio-42/elFinder@2f522db"},"references":[{"type":"ADVISORY","url":"https://github.com/Studio-42/elFinder/blob/68ec63c0aeca3963101aca8f842dc9f2e4c4c6d3/Changelog"},{"type":"FIX","url":"https://github.com/Studio-42/elFinder/commit/2f522db8f037a66ce9040ee0b216aa4a0359286c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:25.406288Z"}}