CVE-2019-9552: Eloan Project Eloan

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.

Affected products

Published 2019-03-04. Last modified 2026-06-17.