Impact
File Browser versions 2.63.6 through 2.63.23 exhibit a flaw where public share links are not cleaned up after a privileged user deletes another user's shared file. This allows attackers to use the stale link to download any new content uploaded to the same directory, bypassing authentication. The weakness corresponds to error handling failure (CWE-459) and results in unauthorized disclosure of data held in shared files.
Affected Systems
The affected product is File Browser from the vendor filebrowser, specifically the filebrowser: filebrowser. Vulnerable releases range from 2.63.6 up to and including 2.63.23. Users running any of these versions should review their deployment for the presence of public share links.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. EPSS data is not available and this issue is not listed in CISA’s KEV catalog. An attacker needs privileged rights to delete files owned by other users; once a privileged account performs such a deletion, the remaining share link can grant unauthenticated access to files uploaded thereafter. Because the flaw depends on privileged actions, the overall risk is limited by the privileged user base, but the impact on confidentiality for each exposed link remains significant.
OpenCVE Enrichment