elFinder 是一个用 JavaScript 和 jQuery UI 编写的开源 Web 文件管理器。在 2.1.70 版本之前, 命令未被包含在 中的 数组中,因此对于这个会改变服务器状态的操作, 函数未被调用。在随软件分发的 默认配置中,FTP 网络挂载处于启用状态,且攻击者可控的协议、主机、路径、端口、用户名、密码、别名及选项参数,会通过 中的 函数流向 。因此,一个跨站请求可以在受害者的会话中持久化一个由攻击者指定的 FTP 挂载,导致 PHP 服务器连接到攻击者指定的 FTP 主机和端口,并在未携带
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81889 | 8.6 HIGH | elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback |
| CVE-2026-81891 | 8.1 HIGH | elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE) |
No comments yet