PT-2026-72003 · Unknown · Filebrowser
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
filebrowser versions prior to 2.63.19
Description
A permission bypass exists in the '/api/resources' endpoint. The
resourceGetHandler function fails to perform a Perm.Download check when processing the checksum parameter. This allows an authenticated user who is restricted from downloading files to obtain a content-hash oracle (supporting md5, sha1, sha256, and sha512) for any file within their scope. This flaw can be used to confirm guessed content, detect changes to files, or perform offline brute-force attacks on files with low entropy.Recommendations
Update to version 2.63.19 or later.
As a temporary mitigation, restrict access to the '/api/resources' endpoint for users who should not have download permissions.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser