Impact
filebrowser versions before 2.63.17 allow an authenticated user to delete a shared directory by supplying a path that ends with a trailing slash, causing the stale public share URL to expose new content that was not intended for public access. This results in unauthorized viewing of files or directories that were previously private, potentially leading to data leakage. The flaw is a path normalization failure, classified as CWE-863.
Affected Systems
The affected product is filebrowser from the filebrowser vendor. All released versions of filebrowser earlier than 2.63.17 contain this flaw; no finer version granularity is documented.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and able to delete and recreate directories; the likely attack vector is an internal user or compromised account. Successful exploitation would provide information disclosure rather than code execution or privilege escalation.
OpenCVE Enrichment