Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh69-9h65-cjx9

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

EPSS

Процентиль: 51%
0.00275
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

EPSS

Процентиль: 51%
0.00275
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22