GHSA-xh6j-gj5f-hrppCriticalCVSS 9.8

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to...

Published
June 17, 2022
Last Modified
July 5, 2026

🔗 CVE IDs covered (1)

📋 Description

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

🔗 References (7)