CVE-2026-81890 | Studio-42 elFinder up to 2.1.69 CSRF Token Validation elFinderConnector.class.php validateCsrfToken protocol/host/path/port/user/pass/alias/options cross-site request forgery
A vulnerability was found in Studio-42 elFinder up to 2.1.69 and classified as problematic. This issue affects the function validateCsrfToken of the file php/elFinderConnector.class.php of the component CSRF Token Validation. Such manipulation of the argument protocol/host/path/port/user/pass/alias/options leads to cross-site request forgery.
This vulnerability is listed as CVE-2026-81890. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More