← Back

CVE-2024-38909

nvd nist
Published: Jul 30, 2024Modified: Apr 28, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

Affected (1)

Products: Std42: Elfinder
1 product
Elfinder
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.1.64

References (4)

Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.