Beveiligingsadvies

CVE-2022-32167

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-09-20 14:45:19
Laatst bijgewerkt 2025-05-29 13:50:36
Toegewezen door Mend
CVSS-score 5.4
Status PUBLISHED

Beschrijving

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.