Beveiligingsadvies

CVE-2024-54909

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-06 00:00:00
Laatst bijgewerkt 2025-02-12 14:12:46
Toegewezen door mitre
CVSS-score 8.1
Status PUBLISHED

Beschrijving

A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.