## https://sploitus.com/exploit?id=SAINT:3DA54F703D2F6D02D8DA113E8435D9DD
Added: 08/28/2023
### Background
[ShareFile](<https://www.sharefile.com/>) is a file sharing service. [StorageZones](<https://docs.sharefile.com/en-us/storage-zones-controller/5-0>) are user-maintained storage for ShareFile data.
### Problem
A vulnerability in ShareFile StorageZones Controller allows remote attackers to upload arbitrary files, leading to command execution.
### Resolution
[Upgrade](<https://www.citrix.com/downloads/sharefile/product-software/sharefile-storagezones-controller-511.html>) to ShareFile StorageZones Controller 5.11.24 or higher.
### References
<https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489>
### Limitations
The uploaded files must be manually removed from the cifs folder after this exploit succeeds.