Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Fri, 25 Oct 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Fri, 25 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Studio42
Studio42 elfinder |
|
CPEs | cpe:2.3:a:studio42:elfinder:*:*:*:*:*:*:*:* | |
Vendors & Products |
Studio42
Studio42 elfinder |
|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-07-30T00:00:00.000Z
Updated: 2025-03-14T18:13:33.092Z
Reserved: 2024-06-21T00:00:00.000Z
Link: CVE-2024-38909

Updated: 2024-08-02T04:19:20.495Z

Status : Awaiting Analysis
Published: 2024-07-30T14:15:02.897
Modified: 2025-03-14T19:15:46.707
Link: CVE-2024-38909

No data.