CVE-2024-26261

CRITICAL

HGiga OAKlouds < 2.0.188/3.0 < 3.0.188 & WebBase < 2.0.1051/3.0 < 3.0.1051 - Unauthenticated Arbitrary File Read/Delete

Title source: llm
STIX 2.1

Description

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html

Scores

CVSS v3 9.8
EPSS 0.0068
EPSS Percentile 47.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (4)
hgiga/oaklouds-organization-2.0 < 188
hgiga/oaklouds-organization-3.0 < 188
hgiga/oaklouds-webbase-2.0 < 1051
hgiga/oaklouds-webbase-3.0 < 1051
Published Feb 15, 2024
Tracked Since Feb 18, 2026