Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-33880


An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.


Published

2024-06-24T17:15:10.353

Last Modified

2025-03-19T18:15:20.963

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application virtosoftware sharepoint_bulk_file_download 5.5.44 Yes
Application microsoft sharepoint_server 2019 No

References