Products
VirtoSoftware Virto Bulk File Download for SharePoint 2019
- 5.5.44
Source
cve@mitre.org
Tags
CVE-2024-33879 details
Published : June 24, 2024, 5:15 p.m.
Last Modified : June 24, 2024, 7:26 p.m.
Last Modified : June 24, 2024, 7:26 p.m.
Description
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
This website uses the NVD API, but is not approved or certified by it.