CVE-2024-54909
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-54909 is a newly disclosed vulnerability in GoldPanKit eva-server version 4.1.0. This issue lies in the /api/resource/local/download endpoint's path parameter, which is susceptible to manipulation. An attacker can exploit this vulnerability to download arbitrary files from the affected system, posing a significant risk to data security. The impact of this vulnerability can range from information disclosure to potential data theft. It is strongly recommended that users of GoldPanKit eva-server version 4.1.0 upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.