漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
Vulnerability Description
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only in letter case (e.g., CaseVictim and casevictim) are stored as distinct accounts but resolve to the same physical home directory, because the scope-ownership check compares the persisted scope as an exact case-sensitive string. A second registrant can therefore read, overwrite, and delete another account's files through authenticated HTTP endpoints, without needing an existing account or victim interaction.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
大小写敏感处理不恰当
Vulnerability Title
File Browser 输入验证错误漏洞
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.19之前版本存在输入验证错误漏洞,该漏洞源于自注册检查主目录所有权时未考虑文件系统不区分大小写的特性,可能导致攻击者通过身份验证的HTTP端点读取、覆盖和删除其他账户的文件。
CVSS Information
N/A
Vulnerability Type
N/A