CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-38909

Critical · CVSS 9.8

studio-42/elfinder — Incorrect Access Control - Unauthorized file copy with arbitrary extension leading to RCE / secret exposure

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
NVD-CWE-noinfo, CWE-284

Description

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

Search profile — drives PoC discovery

Symbols elfinderelFindercopyextensionaccess_controluploadconnectorcmd=copyallowedMimesuploadAllowuploadDenyuploadOrderarchiversnetmount
Keywords CVE-2024-38909elFinder 2.1.64studio-42 elfinderincorrect access controlunauthorized extension copyelfinder RCEelfinder file copy bypasselfinder arbitrary extensionelfinder PoC exploitelfinder server directory traversal
Versions: 2.1.64

Affected packages

Packagist studio-42/elfinder 0 → ∞

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z