top of page
perceptive_background_267k.jpg

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elF…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

elFinder, an open-source web file manager written in JavaScript using jQuery UI, contains an authenticated SQL injection vulnerability in versions prior to 2.1.68. The vulnerability exists in the MySQL volume driver (elFinderVolumeMySQL) and allows any logged-in user, including those with read-only access, to inject SQL commands through a crafted target file hash. Successful exploitation can lead to unauthorized data disclosure and denial of service. The vulnerability only affects installations configured to use the MySQL volume driver and has been fixed in version 2.1.68.

Technical details

Mitigation steps:

Affected products:

elFinder

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page