An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
2024-06-24T17:15:10.257
2024-11-21T09:17:39.790
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | virtosoftware | sharepoint_bulk_file_download | 5.5.44 | Yes |
| Application | microsoft | sharepoint_server | 2019 | No |