PT-2026-25356 · Gokapi · Gokapi
Sijisu
·
Publicado
2026-03-13
·
Atualizado
2026-03-25
·
CVE-2026-30943
CVSS v3.1
4.1
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Gokapi versions prior to 2.2.4
Description
Gokapi is a self-hosted file sharing server. An authorization flaw in the file replace API allows a user with list visibility permission (
UserPermListOtherUploads) to delete another user's file by manipulating the deleteNewFile flag, circumventing the UserPermDeleteOtherUploads requirement. Any authenticated user possessing PERM REPLACE and PERM LIST permissions can delete files belonging to other users without needing PERM DELETE permission.Recommendations
Update Gokapi to version 2.2.4 or later.
Exploit
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gokapi