Impact
This vulnerability is a path traversal and broken access control flaw in the Cloudreve WebDAV implementation. An attacker with a scoped WebDAV credential can use encoded paths such as /dav/%2e%2e/outside.txt to bypass the server’s containment check, enabling unauthorized reading, listing, modifying, or deleting of files that lie outside the configured account directory.
Affected Systems
All installations of Cloudreve running a version prior to 4.16.1 are affected. The vulnerable endpoint is the WebDAV service at /dav. Users on version 4.16.1 or newer are not impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, yet the EPSS score of less than 1% indicates a low likelihood of exploitation in the current landscape. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires possession of a WebDAV credential scoped to an account; once obtained, the attacker can read, list, modify, or delete any file beyond the account’s root.
OpenCVE Enrichment