CVE-2024-51749

LOW

Element <1.11.85 - Info Disclosure

Title source: llm
STIX 2.1

Description

Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.

Scores

CVSS v3 3.5
EPSS 0.0010
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-451
Status published
Products (1)
element-hq/element-web < 1.11.85
Published Nov 12, 2024
Tracked Since Feb 18, 2026