PT-2026-27491 · Onlyoffice+1 · Onlyoffice+1
Bg0D-Glitch
·
Published
2026-03-24
·
Updated
2026-03-24
·
CVE-2026-33330
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FileRise versions prior to 3.10.0
Description
FileRise is a self-hosted web file manager and WebDAV server. A flaw in the access control mechanism within FileRise’s ONLYOFFICE integration permits an authenticated user with read-only permissions to acquire a signed
save callbackUrl for a file. Subsequently, this allows the attacker to manipulate the ONLYOFFICE save callback and overwrite the file with content they control. The affected component is the ONLYOFFICE integration. The vulnerable parameter is the callbackUrl.Recommendations
Update to version 3.10.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filerise
Onlyoffice