File Browser是File Browser组织的一款文件浏览管理软件。 File Browser 2.50.0版本至2.63.21版本存在会话机制问题漏洞,该漏洞源于在代理认证配置了非默认登出页面时未验证JWT过期时间,可能导致攻击者利用先前有效的令牌无限期访问受保护路由和管理端点,并通过续订端点将过期令牌兑换为新令牌。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filebrowser | filebrowser | 2.50.0≤ 2.63.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | 2.50.0 ~ 2.63.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72839 | 9.8 CRITICAL | filebrowser through 2.63.16 Privilege Escalation via Signup |
| CVE-2026-73613 | 8.2 HIGH | filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink |
| CVE-2026-73612 | 8.1 HIGH | File Browser before v2.63.22 Authorization Bypass via Recursive Operations |
No comments yet