CVE-2024-51749
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 451
Summary
CVE-2024-51749 is a vulnerability affecting Element, a Matrix web client built using the React SDK. Prior versions of Element Web and Desktop, specifically those below 1.11.85, fail to verify the consistency of thumbnails for attachments, stickers, and images. An attacker can exploit this issue by adding malicious thumbnails to events, leading to unintended file downloads upon clicking them. The vulnerability has been addressed in Element Web version 1.11.85.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.