PoC Index82,564 CVEs with PoCs

CVE-2026-81890

elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

MEDIUM 5.4EPSS 0.2%

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped php/connector.minimal.php-dist configuration, FTP network mounts are enabled by default, and attacker-controlled protocol, host, path, port, user, pass, alias, and options arguments flow through elFinder::netmount() in php/elFinder.class.php to php/elFinderVolumeFTP.class.php. A cross-site request can therefore persist an attacker-chosen FTP mount in the victim's session, cause the PHP server to connect to an attacker-chosen FTP host and port, and send supplied credentials without an X-elFinder-CSRF token. This issue is fixed in version 2.1.70.

Affected
Studio-42 · elFinder
CVSS v3.1 GITHUB
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
0.15% chance of exploitation in the next 30 days, 5th percentile
Published
2026-08-31
Updated
2026-09-01

Proof-of-concept exploits (1)

References