VYPR

Virto Bulk File Download

by VirtoSoftware

CVEs (3)

  • CVE-2024-33880Jun 24, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.

  • CVE-2024-33879Jun 24, 2024
    risk 0.00cvss epss 0.01

    An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.

  • CVE-2024-33881Jun 24, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.