PT-2025-26978 · Unknown · Filebrowser
Mtausig
·
Published
2025-06-26
·
Updated
2026-03-10
·
CVE-2025-52902
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
File Browser versions prior to 2.33.7
Description:
The Markdown preview function of File Browser is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser.
Recommendations:
For versions prior to 2.33.7, update to version 2.33.7 to resolve the issue. As a temporary workaround, consider disabling the Markdown preview function until the update is applied. Restrict access to uploading Markdown files to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filebrowser