Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-33881


An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.


Published

2024-06-24T17:15:10.447

Last Modified

2024-11-21T09:17:40.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application virtosoftware sharepoint_bulk_file_download 5.5.44 Yes
Application microsoft sharepoint_server 2019 No

References