What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.
Explanation of Vulnerability in Simple Terms
Shared Files versions 1.7.28 and earlier expose sensitive information through improper access controls. An attacker on the network can read data they should not have access to without authentication. The vulnerability affects the confidentiality of stored files but does not allow modification or deletion. Site administrators should update to a version newer than 1.7.28.
What an attacker can do
Read files or data they should not have access to without logging in.
Potential impact on your site
Sensitive files may be exposed to unauthenticated visitors; confidentiality of stored data is at risk.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities