PT-2026-56466 · Unknown · Filebrowser
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
File Browser versions prior to 2.63.16
Description
An issue exists in the ScopedFs component where the system validates the nearest existing ancestor of a dangling symlink as being within scope and subsequently follows that symlink during file creation. This allows an authenticated user possessing Create and Modify permissions to create files outside of their assigned scope.
Recommendations
Update to version 2.63.16.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filebrowser