CVE-2024-38909

July 30, 2024, 2:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Studio 42 elFinder

  • 2.1.64

Source

cve@mitre.org

Tags

CVE-2024-38909 details

Published : July 30, 2024, 2:15 p.m.
Last Modified : July 30, 2024, 2:15 p.m.

Description

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
http://elfinder.com cve@mitre.org
https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 cve@mitre.org
This website uses the NVD API, but is not approved or certified by it.