TROYANOSYVIRUS
Volver a CVEs

CVE-2024-26261

CRITICAL
9.8

Descripcion

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/15/2024
Ultima modificacion1/23/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

hgiga:oaklouds-organization-2.0hgiga:oaklouds-organization-3.0hgiga:oaklouds-webbase-2.0hgiga:oaklouds-webbase-3.0

Debilidades (CWE)

CWE-22

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.