CVE-2022-24633: Filecloud

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.

Affected products

  • Filecloud Filecloud: before 21.3.0.18447 (fixed in 21.3.0.18447)

Published 2022-02-24. Last modified 2026-06-17.