CVE-2024-38909

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Configurations

No configuration.

History

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

Information

Published : 2024-07-30 14:15

Updated : 2025-03-14 19:15


NVD link : CVE-2024-38909

Mitre link : CVE-2024-38909

CVE.ORG link : CVE-2024-38909


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control