Filebrowser

Filebrowser

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 18.08.2026 15:20:10
  • Zuletzt bearbeitet 18.08.2026 18:18:54

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and share...

  • EPSS 0.3%
  • Veröffentlicht 14.08.2026 11:35:42
  • Zuletzt bearbeitet 17.08.2026 16:17:45

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the decla...

  • EPSS 0.3%
  • Veröffentlicht 14.08.2026 11:35:42
  • Zuletzt bearbeitet 14.08.2026 15:17:11

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to ot...

  • EPSS 0.32%
  • Veröffentlicht 14.08.2026 11:35:41
  • Zuletzt bearbeitet 18.08.2026 02:17:28

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confir...

  • EPSS 0.34%
  • Veröffentlicht 14.08.2026 11:35:40
  • Zuletzt bearbeitet 14.08.2026 18:19:08

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with ...

  • EPSS 0.23%
  • Veröffentlicht 14.08.2026 11:35:40
  • Zuletzt bearbeitet 14.08.2026 15:17:10

filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike t...

  • EPSS 0.39%
  • Veröffentlicht 13.08.2026 21:54:39
  • Zuletzt bearbeitet 14.08.2026 17:20:31

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, ...

  • EPSS 0.36%
  • Veröffentlicht 13.08.2026 11:28:16
  • Zuletzt bearbeitet 14.08.2026 21:17:57

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers ca...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 11:28:15
  • Zuletzt bearbeitet 13.08.2026 15:20:19

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by...

  • EPSS 0.27%
  • Veröffentlicht 13.08.2026 11:28:15
  • Zuletzt bearbeitet 14.08.2026 23:16:33

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints...