Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3h9f-mm2x-4j58 | Studio 42 elFinder vulnerable to Incorrect Access Control |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Std42
Std42 elfinder |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:std42:elfinder:2.1.64:*:*:*:*:*:*:* | |
| Vendors & Products |
Std42
Std42 elfinder |
Fri, 14 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 25 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 25 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Studio42
Studio42 elfinder |
|
| CPEs | cpe:2.3:a:studio42:elfinder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Studio42
Studio42 elfinder |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-14T18:13:33.092Z
Reserved: 2024-06-21T00:00:00.000Z
Link: CVE-2024-38909
Updated: 2024-08-02T04:19:20.495Z
Status : Analyzed
Published: 2024-07-30T14:15:02.897
Modified: 2025-04-28T14:35:52.783
Link: CVE-2024-38909
No data.
OpenCVE Enrichment
No data.
Github GHSA