Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.
History

Tue, 26 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Valor Apps
Valor Apps easy Folder Listing Pro
CPEs cpe:2.3:a:valor_apps:easy_folder_listing_pro:3.7:*:*:*:*:*:*:*
cpe:2.3:a:valor_apps:easy_folder_listing_pro:4.4:*:*:*:*:*:*:*
Vendors & Products Valor Apps
Valor Apps easy Folder Listing Pro
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 19:30:00 +0000

Type Values Removed Values Added
Description Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.
Title Easy Folder Listing Pro deserialization vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2024-11-26T19:17:44.520Z

Updated: 2024-11-26T19:39:10.277Z

Reserved: 2024-11-12T15:38:38.803Z

Link: CVE-2024-11145

cve-icon Vulnrichment

Updated: 2024-11-26T19:38:37.377Z

cve-icon NVD

Status : Received

Published: 2024-11-26T20:15:25.270

Modified: 2024-11-26T20:15:25.270

Link: CVE-2024-11145

cve-icon Redhat

No data.