PT-2026-26588 · Filerise · Filerise

N0Rv-Tvt

·

Publicado

2026-03-20

·

Atualizado

2026-03-22

·

CVE-2026-33071

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FileRise versions prior to 3.8.0
Description FileRise is a self-hosted web file manager and WebDAV server. Prior to version 3.8.0, the WebDAV upload endpoint accepts any file extension, including .phtml, .php5, .htaccess, and other server-side executable types. This bypasses the filename validation enforced by the regular upload path. In deployments without Apache’s LocationMatch protection, this can lead to remote code execution. The createFile() method in FileRiseDirectory.php and the put() method in FileRiseFile.php accept filenames directly from the WebDAV client without validation, unlike the regular upload endpoint which uses REGEX FILE NAME for validation.
Recommendations Versions prior to 3.8.0 should be updated to version 3.8.0 or later.

Exploit

Correção

RCE

Unrestricted File Upload

Files Accessible to External Parties

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33071
GHSA-46GV-GF5F-WVR2

Produtos afetados

Filerise