PT-2024-34880 · Element · Element Web+1

Davidegirardi

·

Published

2024-11-12

·

Updated

2024-11-13

·

CVE-2024-51749

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Element Web and Desktop versions prior to 1.11.85
Description The issue concerns the handling of thumbnails for attachments, stickers, and images. Specifically, versions of Element Web and Desktop earlier than 1.11.85 do not check if these thumbnails are coherent. This oversight allows for the possibility of adding thumbnails to events that can trigger a file download once clicked.
Recommendations For versions prior to 1.11.85, update to version 1.11.85 or later to resolve the issue. As a temporary workaround, consider restricting the handling of thumbnails for attachments, stickers, and images until the update is applied.

Exploit

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2024-51749
GHSA-5486-384G-MCX2

Affected Products

Element Desktop
Element Web