216.73.217.174

CVE-2026-33477

· Published 26/03/2026 18:16 · Modified 26/03/2026 19:17

Labels: CVE-2026-33477 2026-03-26CVE-2026-33477CWE-863[email protected]

Essential information

Published
26/03/2026 18:16
Modified
26/03/2026 19:17
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a folder to retrieve snippet content from files uploaded by other users in the same folder. This is a server-side authorization flaw in the `read_own` enforcement for hover previews. Version 3.11.0 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
filerise / filerise cpe:2.3:a:filerise:filerise:2.3.7-3.10.0:*:*:*:*:*:*:*
filerise / filerise cpe:2.3:a:filerise:filerise:3.11.0:*:*:*:*:*:*:*

References