First published: Mon Jun 24 2024(Updated: )
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Virtosoftware Sharepoint Bulk File Download | =5.5.44 | |
Microsoft SharePoint Server 2010 | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33880 is classified as a medium severity vulnerability due to sensitive information disclosure.
CVE-2024-33880 allows attackers to disclose full pathnames, potentially exposing sensitive data on affected systems.
To mitigate CVE-2024-33880, you should apply security updates and patches provided by VirtoSoftware.
CVE-2024-33880 specifically affects Virto Bulk File Download version 5.5.44 for SharePoint 2019.
The exploit vector for CVE-2024-33880 is through the Virto.SharePoint.FileDownloader API with a specific action parameter.