CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
Date published : 2019-02-26
https://github.com/Studio-42/elFinder/blob/master/README.md
https://github.com/Studio-42/elFinder/compare/6884c4f…0740028