SQL Injection Affecting studio-42/elfinder package, versions <2.1.68


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-STUDIO42ELFINDER-16642083
  • published12 May 2026
  • disclosed11 May 2026
  • creditelulq

Introduced: 11 May 2026

NewCVE-2026-44521  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade studio-42/elfinder to version 2.1.68 or higher.

Overview

studio-42/elfinder is an open-source file manager for web, written in JavaScript using jQuery UI.

Affected versions of this package are vulnerable to SQL Injection in the elFinderVolumeMySQL process when handling the target parameter. An attacker can access unauthorized data or cause denial of service by injecting crafted input that manipulates SQL queries. This is only exploitable if the installation is configured to use the MySQL volume driver.

CVSS Base Scores

version 4.0
version 3.1