CVE-2024-54909
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.
Published 2025-02-06. Last modified 2026-06-17.