CVE-2024-35081: Luckyframe Luckyframeweb

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.

Affected products

Published 2024-05-23. Last modified 2026-06-17.