CVE-2024-54909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
06/02/2025
Last modified:
12/02/2025
Description
A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/local/download endpoint, where manipulation of this parameter can lead to arbitrary file download.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH