Impact
File Browser through 2.63.23 applies symbolic links without reapplying the rules to the target. As a result, authenticated users can access files that should be denied by rule sets through symlink aliases. The flaw enables unauthorized reading and overwriting of protected files, compromising confidentiality and integrity. CWE-59 indicates an improper handling of path traversal.
Affected Systems
The vulnerability affects the open‑source File Browser application from the File Browser organization. All releases up to and including version 2.63.23 are susceptible. Versions earlier than 2.63.24 are affected; newer releases contain the fix.
Risk and Exploitability
The CVSS base score is 7.6, indicating high severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid user credentials and a properly configured File Browser instance; therefore the attack vector is for systems exposing rule‑denied files through symbolic links, and prompt remediation is recommended.
OpenCVE Enrichment