Folder architecture and Filesizes of private file drop shares can be getten

Disclosed: 2022-04-09 13:08:38 By shakierbellows To nextcloud
Medium
Vulnerability Details
## Steps To Reproduce: 1. Create a new Folder "TestABC" 2. Share a password protected link of this folder 3. Create a file "README.md" and a file "README.md" in the Subfolder "Subfolder". ==> curl -H "OCS-APIREQUEST: true" "http://localhost/ocs/v2.php/apps/text/public/workspace?shareToken=ABCDE12345" ==> curl -H "OCS-APIREQUEST: true" "http://localhost/ocs/v2.php/apps/text/public/workspace?shareToken=ABCDE12345&folder=subfolder" ## Impact Folder architecture and Filesizes of private file drop shares can be getten
Actions
View on HackerOne
Report Stats
  • Report ID: 1337422
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report