PT-2026-2367 · Unknown · Owlfiles File Manager
Chokri Hammedi
·
Publicado
2026-01-13
·
Atualizado
2026-02-02
·
CVE-2022-50891
CVSS v3.1
5.0
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Owlfiles File Manager version 12.0.1
Description
Owlfiles File Manager contains a cross-site scripting issue that enables attackers to inject malicious scripts. This is achieved by exploiting the
path parameter within HTTP server endpoints, specifically the download and list endpoints. Attackers can construct URLs with embedded script tags to execute arbitrary JavaScript in the browsers of users. The vulnerable parameter is path. The affected API endpoints are the download and list endpoints.Recommendations
Apply any available updates to address this issue. As a temporary workaround, consider sanitizing the
path parameter to prevent the injection of malicious scripts.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Owlfiles File Manager