Loading HuntDB...

Can download files by zipping the folder

Medium
N
Nextcloud
Submitted None

Team Summary

Official summary from Nextcloud

Security advisory at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vhj3-mch4-67fq

Reported by nickvergessen

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
1. Create folder and share it as view-only {F2846936} 2. Access this folder with Testuser {F2846943} 3. Go one level up and compress the whole folder {F2846942} 4. The zip file can be downloaded and extracted locally {F2846939} {F2846941} 5. The folder itself can not be downloaded directly {F2846937} ## Impact Can download files without download permissions

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic