CVE-2024-38909
Critical · CVSS 9.8studio-42/elfinder — Incorrect Access Control - Unauthorized file copy with arbitrary extension leading to RCE / secret exposure
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- NVD-CWE-noinfo, CWE-284
Description
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
Search profile — drives PoC discovery
Symbols elfinderelFindercopyextensionaccess_controluploadconnectorcmd=copyallowedMimesuploadAllowuploadDenyuploadOrderarchiversnetmount
Keywords CVE-2024-38909elFinder 2.1.64studio-42 elfinderincorrect access controlunauthorized extension copyelfinder RCEelfinder file copy bypasselfinder arbitrary extensionelfinder PoC exploitelfinder server directory traversal
Versions: 2.1.64
Affected packages
| Packagist | studio-42/elfinder | 0 → ∞ |
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z