← Volver a CVEs
CVE-2024-26261
CRITICAL9.8
Descripcion
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/15/2024
Ultima modificacion1/23/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
hgiga:oaklouds-organization-2.0hgiga:oaklouds-organization-3.0hgiga:oaklouds-webbase-2.0hgiga:oaklouds-webbase-3.0
Debilidades (CWE)
CWE-22
Referencias
https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96(twcert@cert.org.tw)
https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html(twcert@cert.org.tw)
https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96(af854a3a-2127-422b-91ae-364da2661108)
https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.