An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
2024-06-24T17:15:10.447
2024-11-21T09:17:40.110
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | virtosoftware | sharepoint_bulk_file_download | 5.5.44 | Yes |
| Application | microsoft | sharepoint_server | 2019 | No |