An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 15 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | CWE-200 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-15T19:20:42.987Z
Reserved: 2024-04-28T00:00:00
Link: CVE-2024-33881
Updated: 2024-08-02T02:42:59.800Z
Status : Modified
Published: 2024-06-24T17:15:10.447
Modified: 2024-11-21T09:17:40.110
Link: CVE-2024-33881
No data.
OpenCVE Enrichment
No data.