PT-2025-5875 · Unknown · Goldpankit Eva-Server
Rre1Axo
·
Published
2025-02-06
·
Updated
2025-02-06
·
CVE-2024-54909
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GoldPanKit eva-server version 4.1.0
Description
A vulnerability has been identified that affects the
path parameter of the "/api/resource/local/download" endpoint. Manipulation of this path parameter can lead to arbitrary file download.Recommendations
For GoldPanKit eva-server version 4.1.0, consider restricting access to the "/api/resource/local/download" endpoint until a patch is available. As a temporary workaround, avoid using the
path parameter in this endpoint to minimize the risk of exploitation.Fix
Path traversal
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goldpankit Eva-Server