CVE-2026-15724
8.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Summary
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | ShareFile Storage Zones Controller | 0 <= 5.12.4 | affected |
| Progress | ShareFile Storage Zones Controller | 6.0.0 <= 6.0.1 | affected |
Weaknesses
- CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-73: CWE-73: External Control of File Name or Path
- CWE-20: CWE-20: Improper Input Validation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.