Filestash · Filestash · CVE-2024-41256
**Name of the Vulnerable Software and Affected Versions**
filestash version 0.4
**Description**
The issue is related to the ShareProofVerifier function in filestash, which skips the TLS certificate verification process when sending out email verification codes. This could allow attackers to access sensitive data via a man-in-the-middle attack.
**Recommendations**
For filestash version 0.4, consider disabling the ShareProofVerifier function until a patch is available to enforce TLS certificate verification. Restrict access to sensitive data to minimize the risk of exploitation.