{ "id": "CVE-2024-38909", "sourceIdentifier": "cve@mitre.org", "published": "2024-07-30T14:15:02.897", "lastModified": "2024-07-31T12:57:02.300", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc." }, { "lang": "es", "value": " Studio 42 elFinder 2.1.64 es vulnerable a un control de acceso incorrecto. Copiar archivos con una extensi\u00f3n no autorizada entre directorios de servidores permite a un atacante arbitrario exponer secretos, realizar RCE, etc." } ], "metrics": {}, "references": [ { "url": "http://elfinder.com", "source": "cve@mitre.org" }, { "url": "https://github.com/B0D0B0P0T/CVE/blob/main/CVE-2024-38909", "source": "cve@mitre.org" } ] }