


Perceptive Security
SOC/SIEM Consultancy

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elF…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 19:08:13
Source:
nvd.nist.gov
Web Technologies, Database & Storage
elFinder, an open-source web file manager written in JavaScript using jQuery UI, contains an authenticated SQL injection vulnerability in versions prior to 2.1.68. The vulnerability exists in the MySQL volume driver (elFinderVolumeMySQL) and allows any logged-in user, including those with read-only access, to inject SQL commands through a crafted target file hash. Successful exploitation can lead to unauthorized data disclosure and denial of service. The vulnerability only affects installations configured to use the MySQL volume driver and has been fixed in version 2.1.68.
Technical details
Mitigation steps:
Affected products:
elFinder
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44521
https://github.com/Studio-42/elFinder/security/advisories/GHSA-c3gj-q88f-7hqj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
