Vulnerabilities
Vulnerable Software
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.
CVSS Score
7.2
EPSS Score
0.026
Published
2022-11-23
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.
CVSS Score
5.3
EPSS Score
0.002
Published
2022-02-24
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
CVSS Score
8.8
EPSS Score
0.009
Published
2022-02-16
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
CVSS Score
8.8
EPSS Score
0.001
Published
2022-02-16


Contact Us

Shodan ® - All rights reserved