PT-2026-2367 · Unknown · Owlfiles File Manager
Chokri Hammedi
·
Published
2026-01-13
·
Updated
2026-02-02
·
CVE-2022-50891
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Owlfiles File Manager version 12.0.1
Description
Owlfiles File Manager contains a cross-site scripting issue that enables attackers to inject malicious scripts. This is achieved by exploiting the
path parameter within HTTP server endpoints, specifically the download and list endpoints. Attackers can construct URLs with embedded script tags to execute arbitrary JavaScript in the browsers of users. The vulnerable parameter is path. The affected API endpoints are the download and list endpoints.Recommendations
Apply any available updates to address this issue. As a temporary workaround, consider sanitizing the
path parameter to prevent the injection of malicious scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Owlfiles File Manager