CVE-2024-26261
CRITICALHGiga OAKlouds < 2.0.188/3.0 < 3.0.188 & WebBase < 2.0.1051/3.0 < 3.0.1051 - Unauthenticated Arbitrary File Read/Delete
Title source: llmDescription
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7674-bdb40-1.html
Third Party Advisory third-party-advisory
https://www.chtsecurity.com/news/e456f679-9091-4de4-8f78-9262d20d6a96
Scores
CVSS v3
9.8
EPSS
0.0068
EPSS Percentile
47.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (4)
hgiga/oaklouds-organization-2.0
< 188
hgiga/oaklouds-organization-3.0
< 188
hgiga/oaklouds-webbase-2.0
< 1051
hgiga/oaklouds-webbase-3.0
< 1051
Published
Feb 15, 2024
Tracked Since
Feb 18, 2026