CVE-2024-33118: Luckyframe Luckyframeweb

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

Affected products

Published 2024-05-06. Last modified 2026-06-17.