TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-38909

CRITICAL
9.8

Description

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie7/30/2024
Derniere modification4/28/2025
Sourcenvd
Observations honeypot0

Produits affectes

std42:elfinder

Faiblesses (CWE)

CWE-284

References

http://elfinder.com(cve@mitre.org)
http://elfinder.com(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.