Description
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3h9f-mm2x-4j58 | Studio 42 elFinder vulnerable to Incorrect Access Control |
References
History
Mon, 28 Apr 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Std42
Std42 elfinder |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:std42:elfinder:2.1.64:*:*:*:*:*:*:* | |
| Vendors & Products |
Std42
Std42 elfinder |
Fri, 14 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 25 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Fri, 25 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Studio42
Studio42 elfinder |
|
| CPEs | cpe:2.3:a:studio42:elfinder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Studio42
Studio42 elfinder |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-14T18:13:33.092Z
Reserved: 2024-06-21T00:00:00.000Z
Link: CVE-2024-38909
Updated: 2024-08-02T04:19:20.495Z
Status : Analyzed
Published: 2024-07-30T14:15:02.897
Modified: 2025-04-28T14:35:52.783
Link: CVE-2024-38909
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA