PT-2024-28272 · Studio 42 · Elfinder

Vsevolod Shamov

·

Published

2024-07-30

·

Updated

2025-04-28

·

CVE-2024-38909

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Studio 42 elFinder version 2.1.64
Description The issue allows an arbitrary attacker to expose secrets and perform remote code execution (RCE) by copying files with unauthorized extensions between server directories. This is due to incorrect access control.
Recommendations For Studio 42 elFinder version 2.1.64, consider restricting file copying operations between server directories to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-38909
GHSA-3H9F-MM2X-4J58

Affected Products

Elfinder