CVE-2024-33880: Infoleak
Published Jun 24, 2024
·Updated
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
Affected Software
2 affected components
All of the following
VirtoSoftware Sharepoint Bulk File Download=5.5.44
Microsoft SharePoint Server=2019
Event History
Jun 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33880?
CVE-2024-33880 is classified as a medium severity vulnerability due to sensitive information disclosure.
2
How does CVE-2024-33880 impact Virto Software users?
CVE-2024-33880 allows attackers to disclose full pathnames, potentially exposing sensitive data on affected systems.
3
How do I fix CVE-2024-33880?
To mitigate CVE-2024-33880, you should apply security updates and patches provided by VirtoSoftware.
4
What versions of software are affected by CVE-2024-33880?
CVE-2024-33880 specifically affects Virto Bulk File Download version 5.5.44 for SharePoint 2019.
5
What is the exploit vector for CVE-2024-33880?
The exploit vector for CVE-2024-33880 is through the Virto.SharePoint.FileDownloader API with a specific action parameter.