Executive brief
SHIRASAGI is a content management and groupware system used by organizations for managing websites and shared documents. An authorization bypass vulnerability allows attackers to directly download files from the shared file feature that they should not have access to, potentially exposing sensitive organizational documents and data.
Technical details
The vulnerability is an authorization bypass (CWE-639) in SHIRASAGI's shared file feature where access controls are not properly enforced on file downloads. By directly specifying a file ID in a download request, an unauthenticated or unauthorized attacker can bypass access checks and retrieve files they should not be permitted to access. The vulnerability requires network access to the groupware system but no authentication or special preconditions. The attack vector is straightforward parameter manipulation. SHIRASAGI v1.20.2 and earlier are affected; the issue is fixed in v1.21.0.
Affected products
- SHIRASAGI Project SHIRASAGI v1.20.2 and earlier
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in v1.21.0