PT-2026-49069 · Unknown · Filebrowser
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
File Browser versions prior to 2.63.6
Description
A low-privileged authenticated user with create and delete permissions in their own isolated scope can delete share-link records belonging to any other user, including the administrator. This occurs when the user performs a DELETE operation on a file in their own directory whose logical path is a byte-prefix of another user's stored
share.Link.Path. The issue resides in the resourceDeleteHandler function within http/resource.go, which calls DeleteWithPathPrefix() without verifying the ownership of the share records being deleted. While the contents of the victim's files are not exposed, the share links are irrevocably wiped, potentially leading to a denial-of-service of the share-link feature.Recommendations
Update to version 2.63.6.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser