PT-2023-22025 · Filerun · Filerun

Christian Pöschl

·

Published

2023-12-05

·

Updated

2023-12-11

·

CVE-2023-28875

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Filerun Update 20220202
Description A Stored XSS issue in shared files download terms allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.
Recommendations For Filerun Update 20220202, consider disabling the shared files download feature until a patch is available to prevent exploitation of the Stored XSS issue. Restrict access to shared links to minimize the risk of malicious JavaScript code execution. Avoid using crafted share links in the affected Filerun version until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28875

Affected Products

Filerun