CVE-2024-38909

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
References
Link Resource
http://elfinder.com Permissions Required
https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 Third Party Advisory
http://elfinder.com Permissions Required
https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:std42:elfinder:2.1.64:*:*:*:*:*:*:*

History

28 Apr 2025, 14:35

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:std42:elfinder:2.1.64:*:*:*:*:*:*:*
References () http://elfinder.com - () http://elfinder.com - Permissions Required
References () https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 - () https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 - Third Party Advisory
First Time Std42
Std42 elfinder

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 09:26

Type Values Removed Values Added
References () http://elfinder.com - () http://elfinder.com -
References () https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 - () https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909 -

25 Oct 2024, 18:35

Type Values Removed Values Added
CWE CWE-284

01 Aug 2024, 13:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-284

31 Jul 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Studio 42 elFinder 2.1.64 es vulnerable a un control de acceso incorrecto. Copiar archivos con una extensión no autorizada entre directorios de servidores permite a un atacante arbitrario exponer secretos, realizar RCE, etc.

30 Jul 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 14:15

Updated : 2025-04-28 14:35


NVD link : CVE-2024-38909

Mitre link : CVE-2024-38909

CVE.ORG link : CVE-2024-38909


JSON object : View

Products Affected

std42

  • elfinder
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control