Vulnerabilities
Vulnerable Software
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-02-24
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
CVSS Score
8.8
EPSS Score
0.009
Published
2022-02-16
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
CVSS Score
8.8
EPSS Score
0.001
Published
2022-02-16
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
CVSS Score
5.3
EPSS Score
0.003
Published
2020-10-02
CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.
CVSS Score
8.8
EPSS Score
0.001
Published
2018-07-13


Contact Us

Shodan ® - All rights reserved