Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a folder to retrieve snippet content from files uploaded by other users in the same folder. This is a server-side authorization flaw in the `read_own` enforcement for hover previews. Version 3.11.0 fixes the issue. | |
| Title | FileRise has incorrect authorization in /api/file/snippet.php allows read_own users to read other users’ file content | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-26T18:23:47.892Z
Reserved: 2026-03-20T16:16:48.970Z
Link: CVE-2026-33477
Updated: 2026-03-26T17:46:56.313Z
Status : Received
Published: 2026-03-26T18:16:29.580
Modified: 2026-03-26T19:17:04.017
Link: CVE-2026-33477
No data.
OpenCVE Enrichment
No data.