Executive brief
DivvyDrive, a file storage and management platform, is vulnerable to a security flaw that could allow an attacker to trick a logged-in user into performing unintended actions. By convincing a user to click a malicious link or visit a compromised website, an attacker could modify data or change settings within the user's account without their consent. This could lead to unauthorized data manipulation or administrative changes depending on the victim's permissions.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in DivvyDrive versions 4.8.2.9 through 4.8.3.1. The application fails to properly validate unique tokens for state-changing requests, allowing a remote attacker to craft malicious web pages or links that execute commands in the context of a victim's active session. Successful exploitation requires a victim to be authenticated and interact with a malicious link (User Interaction: Required). This can result in unauthorized integrity impacts, such as modifying user data or system configurations. The issue is addressed in version 4.8.3.2.
Affected products
- DivvyDrive Information Technologies Inc. DivvyDrive 4.8.2.9 to 4.8.3.1
Timeline
- 2026-05-07: advisory: Initial publication by TR-CERT
- 2026-05-10: other: CVSS score updated by TR-CERT