elFinder 是一个基于 JavaScript 和 jQuery UI 编写的开源 Web 文件管理器。在 2.1.70 版本之前,elFinder 在 中的 URL 上传功能在 PHP cURL 不可用时,可能绕过服务端请求伪造(SSRF)防护。原因是 验证的是 ,而 在 cURL 不可用时选择使用 ,该函数会连接 并执行第二次 DNS 解析。能够提交 URL 上传的攻击者可以利用 DNS 重绑定(DNS Rebinding)使第一次解析返回一个公网地址,而实际连接时的解析返回回环地址或私有地址,从而将内部
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81891 | 8.1 HIGH | elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE) |
| CVE-2026-81890 | 5.4 MEDIUM | elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections |
No comments yet