PT-2024-34881 · Unknown · Element Web+1

Davidegirardi

·

Published

2024-11-12

·

Updated

2024-11-13

·

CVE-2024-51750

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Element Web and Desktop versions prior to 1.11.85
Description A malicious homeserver can send invalid messages over federation, which can prevent Element Web and Desktop from rendering single messages or the entire room containing them.
Recommendations For Element Web and Desktop versions prior to 1.11.85, update to version 1.11.85 to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-51750
GHSA-W36J-V56H-Q9PC

Affected Products

Element Desktop
Element Web