PT-2026-27491 · Onlyoffice+1 · Onlyoffice+1

Bg0D-Glitch

·

Publicado

2026-03-24

·

Atualizado

2026-03-24

·

CVE-2026-33330

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions FileRise versions prior to 3.10.0
Description FileRise is a self-hosted web file manager and WebDAV server. A flaw in the access control mechanism within FileRise’s ONLYOFFICE integration permits an authenticated user with read-only permissions to acquire a signed save callbackUrl for a file. Subsequently, this allows the attacker to manipulate the ONLYOFFICE save callback and overwrite the file with content they control. The affected component is the ONLYOFFICE integration. The vulnerable parameter is the callbackUrl.
Recommendations Update to version 3.10.0 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33330
GHSA-6C3J-F4X4-36M3

Produtos afetados

Filerise
Onlyoffice