Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
filebrowser through 2.63.16 Privilege Escalation via Signup
Vulnerability Description
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权授予不正确
Vulnerability Title
File Browser 权限许可和访问控制问题漏洞
Vulnerability Description
File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.63.16及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于启用自助注册并使用默认CreateUserDir设置时未正确限制范围和权限,可能导致未经身份验证的攻击者注册账户并继承服务器根范围,获得创建、修改、删除、重命名、共享和下载全部文件的完整权限,从而不受限制访问所有文件。
CVSS Information
N/A
Vulnerability Type
N/A