David Langley

2 exploits Active since Nov 2024
CVE-2024-51749 WRITEUP LOW WRITEUP
Element <1.11.85 - Info Disclosure
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.
CVSS 3.5
CVE-2024-51750 WRITEUP MEDIUM WRITEUP
Element <1.11.85 - Info Disclosure
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
CVSS 5.0