CVE-2024-35081: Luckyframe Luckyframeweb
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in the fileDownload method.
Affected products
- Luckyframe Luckyframeweb: version 3.5.2 only
Published 2024-05-23. Last modified 2026-06-17.