CVE-2024-54909
06.02.2025, 22:15
A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.
Awaiting analysis
This vulnerability is currently awaiting analysis.