Local File Inclusion Vulnerability in dhtmlxFileExplorer by DHTMLX
CVE-2024-55214

6.5MEDIUM

Key Information:

Vendor

DHTMLX

Vendor
CVE Published:
7 February 2025

What is CVE-2024-55214?

A Local File Inclusion vulnerability exists in dhtmlxFileExplorer v8.4.6 that allows a remote attacker to exploit the file download functionality. By manipulating requests, an attacker can gain access to sensitive information on the server, leading to potential data leaks and further exploitation of security weaknesses. It is essential for users to review their configurations and apply necessary patches to safeguard their systems.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.