Impact
A missing-authentication flaw in the deleteShareLink endpoint of FileRise allows an external attacker to send an unauthenticated HTTP POST request with a share token, causing the server to delete that share link. This action removes the link permanently, effectively preventing any user who relies on that link from accessing the shared file, which amounts to a denial of service for those shared resources.
Affected Systems
FileRise self-hosted web file manager and WebDAV server versions prior to 3.8.0 released by error311 are vulnerable. Attackers only need the share token to exploit the fault; no credentials or additional access are required.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and an EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog. The weak security model (absence of authentication and validation) means that an attacker poses a low effort, high impact risk to any site running a vulnerable version.
OpenCVE Enrichment