PT-2025-48574 · Filerise · Filerise
Published
2025-12-01
·
Updated
2026-01-07
·
CVE-2025-66403
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FileRise versions prior to 2.2.3
Description
FileRise is a self-hosted web-based file manager. A stored cross-site scripting (XSS) issue exists due to improper handling of uploaded SVG files. The application accepts user-supplied SVG uploads without sanitizing or restricting embedded script content. When a malicious SVG containing inline JavaScript or event-based payloads is uploaded, it is rendered in the browser when viewed within the application. SVGs are XML-based and allow scripting, executing in the origin context of the application, enabling full stored XSS.
Recommendations
Update to version 2.2.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filerise