CVE-2024-11145

CRITICAL

Easy Folder Listing Pro < 4.5 - Unauthenticated Remote Code Execution via Deserialization

Title source: llm
STIX 2.1

Description

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.

Scores

CVSS v3 9.8
EPSS 0.0097
EPSS Percentile 57.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
valorapps/easy_folder_listing_pro 3.7
valorapps/easy_folder_listing_pro 4.4 - 4.5
Published Nov 26, 2024
Tracked Since Feb 18, 2026