Логотип exploitDog
bind:CVE-2025-52900
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-52900

Количество 2

Количество 2

nvd логотип

CVE-2025-52900

8 месяцев назад

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same is true for the database used by File Browser. On standard servers using File Browser prior to version 2.33.7 where the umask configuration has not been hardened before, this makes all the stated files readable by any operating system account. Version 2.33.7 fixes the issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-jj2r-455p-5gvf

8 месяцев назад

filebrowser Sets Insecure File Permissions

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-52900

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same is true for the database used by File Browser. On standard servers using File Browser prior to version 2.33.7 where the umask configuration has not been hardened before, this makes all the stated files readable by any operating system account. Version 2.33.7 fixes the issue.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-jj2r-455p-5gvf

filebrowser Sets Insecure File Permissions

CVSS3: 5.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу