Critical severity9.8NVD Advisory· Published Jun 24, 2024· Updated Jun 17, 2026
CVE-2024-33879
CVE-2024-33879
Description
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:virtosoftware:sharepoint_bulk_file_download:5.5.44:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=5.5.44
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.