CVE-2024-38909: STD42 Elfinder
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Affected products
- STD42 Elfinder: version 2.1.64 only
Published 2024-07-30. Last modified 2026-07-09.