elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
The vulnerability occurs when performing image operations on JPEG files, where the filename
is passed to the `exiftran` utility without proper sanitization, allowing command injection.
id: CVE-2019-9194
info:
name: elFinder <= 2.1.47 - Command Injection
author: r00tuser111
seve
...