Описание
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
Ссылки
EPSS
Процентиль: 10%
0.00198
Низкий
3.1 Low
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 3.1
github
около 1 месяца назад
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
EPSS
Процентиль: 10%
0.00198
Низкий
3.1 Low
CVSS3
Дефекты
CWE-863