PT-2024-34880 · Element · Element Web+1

·

CVE-2024-51749

·

Published

2024-11-12

·

Updated

2024-11-13

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Element Web and Desktop versions prior to 1.11.85
Description The issue concerns the handling of thumbnails for attachments, stickers, and images. Specifically, versions of Element Web and Desktop earlier than 1.11.85 do not check if these thumbnails are coherent. This oversight allows for the possibility of adding thumbnails to events that can trigger a file download once clicked.
Recommendations For versions prior to 1.11.85, update to version 1.11.85 or later to resolve the issue. As a temporary workaround, consider restricting the handling of thumbnails for attachments, stickers, and images until the update is applied.

Exploit

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51749
GHSA-5486-384G-MCX2

Affected Products

Element Desktop
Element Web