Files.com – Auth Bypass (Fat Client)

Posted by Balázs Hambalkó on Jan 06

Hi,

Vendor: Files.com
Product: Fat Client
Tested version: 3.3.6 but newer version high likely also affected
Credit: Balazs Hambalko, IT Security Consultant

This vulnerability was identified and reported promptly to the vendor in
April 2020.
The answer was they do not see any risk here.

Anyway I would like to share my POC video, only for learning purposes.

According to the vendor, there is no risk here, on the other hand, I built
up a…

If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.

Discord

Original Source