CVE-2019-9194
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 97%
from disclosure to weapon6 days
Published on NVDFeb 26
1st PoC+6d
metasploitFeb 26
VulnCheck+635d
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Affected products
n/a · n/apublic PoCs found — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46481exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46539githubgithub.com/estebanzarate/CVE-2019-9194-elFinder-Command-Injection-PoC★ 2githubgithub.com/cved-sources/cve-2019-9194★ 0cve_referencewww.exploit-db.com/exploits/46481/unverifiedvulncheckvulncheck.com/xdb/2ddd39e09a2dunverifiedcve_referencewww.exploit-db.com/exploits/46539/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.