PT-2026-26587 · Filerise · Filerise
N0Rv-Tvt
·
Publicado
2026-03-20
·
Atualizado
2026-03-22
·
CVE-2026-33070
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
FileRise versions prior to 3.8.0
Description
FileRise is a self-hosted web file manager and WebDAV server. A missing authentication check in the
deleteShareLink endpoint allows unauthenticated users to delete arbitrary file share links by providing only the share token, leading to denial of service for shared file access. The /api/file/deleteShareLink.php API endpoint calls the FileController::deleteShareLink() function, which does not perform authentication, authorization, or CSRF validation before deleting a share link. Any anonymous HTTP client can destroy share links. The vulnerable parameter is the share token.Recommendations
Update FileRise to version 3.8.0 or later.
Exploit
Correção
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Filerise