CVE-2024-26261: Hgiga OAKlouds - Arbitrary File Read And Delete
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OAKlouds-organization-2.0to a version that resolves this vulnerability.Fixed in 188 - Upgrade
Upgrade
OAKlouds-organization-3.0to a version that resolves this vulnerability.Fixed in 188 - Upgrade
Upgrade
OAKlouds-webbase-2.0to a version that resolves this vulnerability.Fixed in 1051 - Upgrade
Upgrade
OAKlouds-webbase-3.0to a version that resolves this vulnerability.Fixed in 1051
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26261?
CVE-2024-26261 is classified as a critical vulnerability due to its potential for arbitrary file read and deletion.
How do I fix CVE-2024-26261?
To fix CVE-2024-26261, it is recommended to implement input validation and restrict access to file download functionalities.
What are the potential impacts of CVE-2024-26261?
Exploitation of CVE-2024-26261 may lead to unauthorized access to sensitive files and permanent deletion of files from the server.
Which software is affected by CVE-2024-26261?
CVE-2024-26261 affects various modules of the HGiga OAKlouds software, specifically versions prior to 188 for 2.0 and 3.0, as well as webbase versions prior to 1051.
Is authentication required to exploit CVE-2024-26261?
No, CVE-2024-26261 allows attackers to download and delete files without any authentication.