PT-2026-2367 · Unknown · Owlfiles File Manager

Chokri Hammedi

·

Publicado

2026-01-13

·

Atualizado

2026-02-02

·

CVE-2022-50891

CVSS v3.1

5.0

Média

VetorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Owlfiles File Manager version 12.0.1
Description Owlfiles File Manager contains a cross-site scripting issue that enables attackers to inject malicious scripts. This is achieved by exploiting the path parameter within HTTP server endpoints, specifically the download and list endpoints. Attackers can construct URLs with embedded script tags to execute arbitrary JavaScript in the browsers of users. The vulnerable parameter is path. The affected API endpoints are the download and list endpoints.
Recommendations Apply any available updates to address this issue. As a temporary workaround, consider sanitizing the path parameter to prevent the injection of malicious scripts.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-50891

Produtos afetados

Owlfiles File Manager