Description
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-29509 | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:13:57.045Z
Reserved: 2022-02-07T00:00:00.000Z
Link: CVE-2022-24633
No data.
Status : Modified
Published: 2022-02-24T15:15:29.867
Modified: 2024-11-21T06:50:46.840
Link: CVE-2022-24633
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD