Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.
History

Tue, 23 Sep 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Valorapps
Valorapps easy Folder Listing Pro
CPEs cpe:2.3:a:valorapps:easy_folder_listing_pro:*:*:*:*:*:joomla\!:*:*
cpe:2.3:a:valorapps:easy_folder_listing_pro:3.7:*:*:*:*:joomla\!:*:*
Vendors & Products Valorapps
Valorapps easy Folder Listing Pro

Tue, 26 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Valor Apps
Valor Apps easy Folder Listing Pro
CPEs cpe:2.3:a:valor_apps:easy_folder_listing_pro:3.7:*:*:*:*:*:*:*
cpe:2.3:a:valor_apps:easy_folder_listing_pro:4.4:*:*:*:*:*:*:*
Vendors & Products Valor Apps
Valor Apps easy Folder Listing Pro
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 19:30:00 +0000

Type Values Removed Values Added
Description Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the Joomla! application. Fixed in versions 3.8 and 4.5.
Title Easy Folder Listing Pro deserialization vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2024-11-26T19:39:10.277Z

Reserved: 2024-11-12T15:38:38.803Z

Link: CVE-2024-11145

cve-icon Vulnrichment

Updated: 2024-11-26T19:38:37.377Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-26T20:15:25.270

Modified: 2025-09-23T13:17:51.417

Link: CVE-2024-11145

cve-icon Redhat

No data.