Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
References
Configurations
No configuration.
History
14 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 |
Information
Published : 2024-07-30 14:15
Updated : 2025-03-14 19:15
NVD link : CVE-2024-38909
Mitre link : CVE-2024-38909
CVE.ORG link : CVE-2024-38909
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control