PT-2025-48574 · Filerise · Filerise

Published

2025-12-01

·

Updated

2026-01-07

·

CVE-2025-66403

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FileRise versions prior to 2.2.3
Description FileRise is a self-hosted web-based file manager. A stored cross-site scripting (XSS) issue exists due to improper handling of uploaded SVG files. The application accepts user-supplied SVG uploads without sanitizing or restricting embedded script content. When a malicious SVG containing inline JavaScript or event-based payloads is uploaded, it is rendered in the browser when viewed within the application. SVGs are XML-based and allow scripting, executing in the origin context of the application, enabling full stored XSS.
Recommendations Update to version 2.2.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66403
GHSA-QRCV-VJVF-FR29

Affected Products

Filerise