PT-2025-42793 · Filerise · Filerise

CVE-2025-62510

·

Publicado

2025-10-20

·

Atualizado

2025-12-04

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FileRise versions prior to 1.5.0
Description FileRise is a self-hosted web-based file manager offering multi-file upload, editing, and batch operations. A regression in version 1.4.0 permitted the inference of folder visibility and ownership based on folder names. This allowed low-privilege users to view or interact with folders matching their username and, in certain instances, access content belonging to other users. The issue was addressed in version 1.5.0 by implementing explicit per-folder Access Control Lists (ACLs) – defining owners, read, write, share, and read own permissions – and enforcing strict server-side checks across various paths including list, read, write, share, rename, copy/move, zip, and WebDAV.
Recommendations Upgrade to FileRise version 1.5.0 or later.

Exploit

Correção

LPE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-62510
GHSA-JM96-2W52-5QJJ

Produtos afetados

Filerise