Security advisories
2018
During my application security work, together with Anthony Maia, I discovered nine security issues in Vaultize Enterprise File Sharing version 17.05.31. Vaultize is an enterprise file security platform providing continuous data protection, digital rights management and secure file sharing. Following the coordinated disclosure process of CERT-XLM (Excellium Services, now Thales Cyber Solutions Luxembourg), eight of these issues were assigned the following CVEs, published in April 2018:
- CVE-2018-10206: Stored XSS via the optional message field of a file request
- CVE-2018-10207: Missing authorization on the FlexPaperViewer SWF reader
- CVE-2018-10208: Anonymous reflected XSS on the error page
- CVE-2018-10209: Stored XSS on the file or folder download pop-up
- CVE-2018-10210: User enumeration through the password-reset feature
- CVE-2018-10211: Improper authorization when listing the history of another user
- CVE-2018-10212: Improper authorization leading to creation of folders in another account
- CVE-2018-10213: XSS in invitation mail