Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVSS
No CVSS.
References
Configurations
No configuration.
History
30 Jul 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-30 14:15
Updated : 2024-07-30 14:15
NVD link : CVE-2024-38909
Mitre link : CVE-2024-38909
CVE.ORG link : CVE-2024-38909
JSON object : View
Products Affected
No product.
CWE
No CWE.