An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-06-24 17:15
Updated : 2024-07-03 01:59
NVD link : CVE-2024-33881
Mitre link : CVE-2024-33881
CVE.ORG link : CVE-2024-33881
JSON object : View
Products Affected
microsoft
- sharepoint_server
virtosoftware
- sharepoint_bulk_file_download