Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Oct 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Fri, 25 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Studio42
Studio42 elfinder |
|
CPEs | cpe:2.3:a:studio42:elfinder:*:*:*:*:*:*:*:* | |
Vendors & Products |
Studio42
Studio42 elfinder |
|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-30T00:00:00
Updated: 2024-10-25T17:25:18.858Z
Reserved: 2024-06-21T00:00:00
Link: CVE-2024-38909
Vulnrichment
Updated: 2024-08-02T04:19:20.495Z
NVD
Status : Awaiting Analysis
Published: 2024-07-30T14:15:02.897
Modified: 2024-11-21T09:26:59.560
Link: CVE-2024-38909
Redhat
No data.