PT-2026-91742 · Zfile · Zfile
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZFile versions prior to 5.0.6
Description
The download endpoint fails to validate requested file paths against the allowed entries of a share link. This allows an attacker with a valid share link to provide arbitrary file paths as query parameters to download any file located under the shared base directory, bypassing intended access restrictions.
Recommendations
Update to version 5.0.6 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zfile