Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
File Browser before 2.63.20 Privilege Escalation via Proxy Authentication
Vulnerability Description
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
File Browser 权限许可和访问控制问题漏洞
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.20之前版本存在权限许可和访问控制问题漏洞,该漏洞源于代理和钩子身份验证自动配置路径中未能遵循createUserDir隔离,可能导致具有有效上游认证凭据的攻击者利用服务器根作用域分配读取、修改、删除和共享其他用户的文件。
CVSS Information
N/A
Vulnerability Type
N/A