CVE-2025-52901
- EPSS 0.49%
- Veröffentlicht 30.06.2025 19:56:25
- Zuletzt bearbeitet 04.08.2025 18:15:35
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is us...
- EPSS 0.89%
- Veröffentlicht 26.06.2025 18:21:03
- Zuletzt bearbeitet 09.06.2026 11:16:46
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions of the web application on the 2.x branch, all users have a scope assigned, and they only ha...
- EPSS 0.97%
- Veröffentlicht 26.06.2025 18:16:32
- Zuletzt bearbeitet 09.06.2026 13:16:35
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions on the 2.x branch prior to 2.33.10, the Command Execution feature of File Browser only allo...
CVE-2025-52902
- EPSS 0.27%
- Veröffentlicht 26.06.2025 14:37:45
- Zuletzt bearbeitet 10.07.2025 01:09:35
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scrip...
CVE-2025-52900
- EPSS 0.2%
- Veröffentlicht 26.06.2025 14:35:50
- Zuletzt bearbeitet 10.07.2025 01:17:03
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set...
- EPSS 0.73%
- Veröffentlicht 16.09.2023 01:15:07
- Zuletzt bearbeitet 27.03.2025 14:42:46
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.
CVE-2021-46398
- EPSS 6.66%
- Veröffentlicht 04.02.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:34:02
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run ...