CVE-2022-24633: Filecloud
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "path" passing "/SHARED/<username>". A malicious actor could identify the existence of users by requesting share information on specified share paths.
Affected products
- Filecloud Filecloud: before 21.3.0.18447 (fixed in 21.3.0.18447)
Published 2022-02-24. Last modified 2026-06-17.