Lucene search

K
cvelistMitreCVELIST:CVE-2024-33879
HistoryJun 24, 2024 - 12:00 a.m.

CVE-2024-33879

2024-06-2400:00:00
mitre
www.cve.org
5
virtosoftware
bulk file download
sharepoint 2019
absolute path traversal
arbitrary file download
deletion

EPSS

0.001

Percentile

39.5%

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

EPSS

0.001

Percentile

39.5%

Related for CVELIST:CVE-2024-33879