Description
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 15 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | CWE-200 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-15T19:20:42.987Z
Reserved: 2024-04-28T00:00:00.000Z
Link: CVE-2024-33881
Updated: 2024-08-02T02:42:59.800Z
Status : Modified
Published: 2024-06-24T17:15:10.447
Modified: 2024-11-21T09:17:40.110
Link: CVE-2024-33881
No data.
OpenCVE Enrichment
No data.