Impact
File Browser versions earlier than 2.63.20 allow an authenticated attacker with upstream credentials to bypass the intended isolation of user directories. The bug occurs because the createUserDir check is ignored in proxy and hook authentication auto‑provisioning paths, letting the attacker read, modify, delete, and share files that belong to other users. This exposes not only the confidentiality of other users’ data but also its integrity and availability, and it facilitates lateral movement within the system.
Affected Systems
The vulnerability affects all deployments of File Browser whose product name is "File Browser" by the vendor "File Browser" where the installed version is earlier than 2.63.20. No specific sub‑components are mentioned beyond the core proxy and hook authentication mechanisms.
Risk and Exploitability
The CVSS score is 8.7, indicating a high‑severity flaw. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, but the ability to elevate privileges from an upstream‑authenticated context makes the vulnerability practically exploitable on systems with exposed proxy authentication. An adversary who compromises or guesses a valid upstream credential can immediately gain the ability to manipulate other users’ files, posing a serious threat in multi‑tenant or shared environments.
OpenCVE Enrichment