PT-2026-84021 · Elfinder · Elfinder
CVE-2026-81890
·
Published
2026-08-31
·
Updated
2026-09-02
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
elFinder versions prior to 2.1.70
Description
The
netmount command is missing from the elFinderConnector::$csrfProtectedCmds list in php/elFinderConnector.class.php, which prevents the validateCsrfToken() function from being executed during this state-changing operation. In the default php/connector.minimal.php-dist configuration, FTP network mounts are enabled. This allows a cross-site request to bypass the X-elFinder-CSRF token requirement and pass attacker-controlled arguments—including protocol, host, path, port, user, pass, alias, and options—through elFinder::netmount() in php/elFinder.class.php to php/elFinderVolumeFTP.class.php. Consequently, an attacker can force the PHP server to connect to an arbitrary FTP host and port using supplied credentials and persist an attacker-chosen FTP mount within the victim's session.Recommendations
Update to version 2.1.70.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elfinder