CVE-2024-26261

EUVD-2024-23537
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
hgigaoaklouds-organization-2.0
𝑥
< 188
hgigaoaklouds-organization-3.0
𝑥
< 188
hgigaoaklouds-webbase-2.0
𝑥
< 1051
hgigaoaklouds-webbase-3.0
𝑥
< 1051
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
hgigaoaklouds-organization
𝑥
< 188
ADP
hgigaoaklouds-organization
𝑥
< 188
ADP
hgigaoaklouds-webbase
𝑥
< 1051
ADP
hgigaoaklouds-webbase
𝑥
< 1051
ADP