Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
Vulnerability Description
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
error311 FileRise 路径遍历漏洞
Vulnerability Description
error311 FileRise是error311的文件管理。 error311 FileRise 3.16.0之前版本存在安全漏洞,该漏洞源于上传端点对文件名验证不当,允许URL编码的路径分隔符绕过过滤,可能导致路径遍历和任意文件写入,进而导致管理员账户接管。
CVSS Information
N/A
Vulnerability Type
N/A