Vulnerabilities > Filecloud

DATE CVE VULNERABILITY TITLE RISK
2022-11-23 CVE-2022-39833 Unspecified vulnerability in Filecloud
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.
network
low complexity
filecloud
7.2
2022-06-15 CVE-2022-1958 Improper Access Control vulnerability in Filecloud
A vulnerability classified as critical has been found in FileCloud.
network
low complexity
filecloud CWE-284
6.5
2022-02-24 CVE-2022-24633 Information Exposure vulnerability in Filecloud
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration.
network
low complexity
filecloud CWE-200
5.0
2022-02-16 CVE-2022-25241 Cross-Site Request Forgery (CSRF) vulnerability in Filecloud
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
network
high complexity
filecloud CWE-352
5.1
2022-02-16 CVE-2022-25242 Cross-Site Request Forgery (CSRF) vulnerability in Filecloud
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
network
high complexity
filecloud CWE-352
5.1
2020-10-02 CVE-2020-26524 Unspecified vulnerability in Filecloud
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
network
low complexity
filecloud
5.0
2018-07-13 CVE-2016-6578 Cross-Site Request Forgery (CSRF) vulnerability in Filecloud
CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability.
network
filecloud CWE-352
6.8