CVE-2021-46398
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
04/02/2022
Last modified:
04/03/2022
Description
A Cross-Site Request Forgery vulnerability exists in Filebrowser
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | 2.18.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/165885/FileBrowser-2.17.2-Code-Execution-Cross-Site-Request-Forgery.html
- https://febin0x4e4a.blogspot.com/2022/01/critical-csrf-in-filebrowser.html
- https://febin0x4e4a.wordpress.com/2022/01/19/critical-csrf-in-filebrowser/
- https://febinj.medium.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7
- https://github.com/filebrowser/filebrowser/commit/74b7cd8e81840537a8206317344f118093153e8d
- https://systemweakness.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7



