Cross-Site Request Forgery in Filebrowser
High severity
GitHub Reviewed
Published
Feb 5, 2022
to the GitHub Advisory Database
•
Updated May 20, 2024
Package
Affected versions
< 2.18.0
Patched versions
2.18.0
Description
Published by the National Vulnerability Database
Feb 4, 2022
Published to the GitHub Advisory Database
Feb 5, 2022
Reviewed
Feb 8, 2022
Last updated
May 20, 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.
References