S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2019-9194 Scanner

CVE-2019-9194 Scanner - Command Injection vulnerability in elFinder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9194
9.8
CVSS

elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

elFinder is a file manager for web applications widely used by developers to integrate file management capabilities into their software. It serves as a crucial component in content management systems, media libraries, and collaborative platforms. Developers from various industries employ elFinder due to its robust features and flexibility, facilitating effective file operations in a web interface. The software can be connected through various backends like PHP, Python, etc., and supports high-level security configurations. Despite its features, it requires consistent updates to safeguard against vulnerabilities. Users appreciate elFinder for simplifying the complex task of handling files and directories over web applications.

The scanner identifies a Command Injection vulnerability present in elFinder before version 2.1.48. This vulnerability can be exploited through the PHP connector, specifically while performing image operations on JPEG files. The improper sanitation of filenames before being passed to the `exiftran` utility allows malicious commands to execute. Exploits involving such vulnerabilities can lead to unauthorized code execution on the server. It necessitates prompt detection and mitigation to prevent potential breaches. Command Injection vulnerabilities are critical concerns that demand immediate attention from web administrators.

Technically, the Command Injection arises when file names undergo inappropriate handling in the PHP connector. The vulnerability takes advantage of the image processing library associated with JPEG operations. During processing, filenames are mishandled by `exiftran`, allowing shell commands to pass unfiltered. The end point involved in this process facilitates unauthorized command execution, compromising the system’s integrity. Attackers can craft payloads to execute commands through file uploads. The vulnerability leverages the inadequate input sanitization implementation, risking code execution at the server level.

If exploited, the Command Injection vulnerability in elFinder can lead to severe security implications. An attacker can execute arbitrary commands on the server, potentially gaining unauthorized access to sensitive data. This could also result in service disruptions, data corruption, or a system takeover, posing risks of unauthorized data manipulation. Exploiting this flaw might open the door for further attacks, extending the impact beyond the initial breach. Organizations using vulnerable versions could face privacy violations and reputational damage. Immediate patching and safeguards are vital to protect against such threats.

REFERENCES

Solution Advice
  • Update elFinder to version 2.1.48 or newer to patch the known vulnerability.
  • Implement strict input validation and sanitation on file uploads to prevent command injection.
  • Regularly audit and monitor server logs to detect any unusual activity indicative of command injection attempts.
  • Apply security patches promptly to minimize exposure to known vulnerabilities.
  • Consider employing intrusion detection systems to alert on suspicious file activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.