CVE-2024-38909: Critical severity std42 elFinder vulnerability
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38909?
CVE-2024-38909 is classified as a high severity vulnerability due to its impact on access control and potential for remote code execution.
How do I fix CVE-2024-38909?
To fix CVE-2024-38909, upgrade to a version of elFinder newer than 2.1.64, which addresses the incorrect access control issue.
What are the potential risks associated with CVE-2024-38909?
CVE-2024-38909 allows attackers to copy files with unauthorized extensions, potentially leading to data exposure and remote code execution.
Which versions of elFinder are affected by CVE-2024-38909?
CVE-2024-38909 affects elFinder version 2.1.64 and earlier.
Who can exploit CVE-2024-38909?
Any attacker with access to the server directories can exploit CVE-2024-38909 to perform unauthorized actions.