← Voltar à pesquisa de CVEs

CVE-2026-62684

File Browser

Descrição

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and shareGetsHandler through renderJSON, causing POST /api/share/{path} and GET /api/shares to expose password_hash and the bypass token, while an administrator can retrieve these secrets for every user-s shares, enabling offline password cracking and direct access to protected shares. This issue is fixed in version 2.63.17.

CVSS 2.7EPSS 0.393%Risco 0.28
Ver fonte
Publicação
2026-08-18 16:18:11
Versões afetadas
<2.63.17
Tipo
Aplicação web
Última alteração
2026-08-18 18:18:54
Vetor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N