PT-2026-93816 · Error311+1 · Filerise
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FileRise versions prior to 3.28.0
Description
Improper session isolation between the WebDAV interface and the web application session context allows authenticated low-privilege attackers to gain unauthorized read and write access. By combining valid Basic-Auth credentials with an active admin
PHPSESSID cookie, attackers can bypass authorization boundaries. This occurs because the WebDAV layer incorrectly inherits elevated privileges from an ambient web session instead of enforcing independent stateless authentication as required by RFC 4918.Recommendations
Update to version 3.28.0 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filerise