CVE-2019-9552: Eloan Project Eloan
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
Affected products
- Eloan Project Eloan: from 3.0, up to and including 2018-09-20
Published 2019-03-04. Last modified 2026-06-17.