PT-2025-42793 · Filerise · Filerise
Published
2025-10-20
·
Updated
2025-12-04
·
CVE-2025-62510
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FileRise versions prior to 1.5.0
Description
FileRise is a self-hosted web-based file manager offering multi-file upload, editing, and batch operations. A regression in version 1.4.0 permitted the inference of folder visibility and ownership based on folder names. This allowed low-privilege users to view or interact with folders matching their username and, in certain instances, access content belonging to other users. The issue was addressed in version 1.5.0 by implementing explicit per-folder Access Control Lists (ACLs) – defining owners, read, write, share, and read own permissions – and enforcing strict server-side checks across various paths including list, read, write, share, rename, copy/move, zip, and WebDAV.
Recommendations
Upgrade to FileRise version 1.5.0 or later.
Exploit
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filerise