PT-2023-22025 · Filerun · Filerun
Christian Pöschl
·
Published
2023-12-05
·
Updated
2023-12-11
·
CVE-2023-28875
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Filerun Update 20220202
Description
A Stored XSS issue in shared files download terms allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.
Recommendations
For Filerun Update 20220202, consider disabling the shared files download feature until a patch is available to prevent exploitation of the Stored XSS issue. Restrict access to shared links to minimize the risk of malicious JavaScript code execution. Avoid using crafted share links in the affected Filerun version until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filerun