CVE-2024-51749

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 451

Summary

CVE-2024-51749 is a vulnerability affecting Element, a Matrix web client built using the React SDK. Prior versions of Element Web and Desktop, specifically those below 1.11.85, fail to verify the consistency of thumbnails for attachments, stickers, and images. An attacker can exploit this issue by adding malicious thumbnails to events, leading to unintended file downloads upon clicking them. The vulnerability has been addressed in Element Web version 1.11.85.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share