Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-39612

Disclosure Date: September 16, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.
Attacker Value
Unknown

CVE-2021-46398

Disclosure Date: February 04, 2022 (last updated October 07, 2023)
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.
Attacker Value
Unknown

CVE-2021-37794

Disclosure Date: August 31, 2021 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user authorized to upload a malicious .svg file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger malicious OS commands on the server running the FileBrowser instance.
Attacker Value
Unknown

CVE-2013-2036

Disclosure Date: June 24, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."
0
Attacker Value
Unknown

CVE-2008-6342

Disclosure Date: February 27, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the TYPO3 Simple File Browser (simplefilebrowser) extension 1.0.2 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors.
0