CVE-2021-46398
HIGH8.8EPSS 10.3%Cross-Site Request Forgery in Filebrowser
發布日:2022/2/5修改日:2024/5/20
描述
A Cross-Site Request Forgery (CSRF) vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.
受影響套件(2)
- Go/github.com/filebrowser/filebrowser/v2from 0, < 2.18.0
- Go/github.com/filebrowser/filebrowser/v2from 0, < 2.18.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-46398
- WEBhttp://packetstormsecurity.com/files/165885/FileBrowser-2.17.2-Code-Execution-Cross-Site-Request-Forgery.html
- WEBhttps://febin0x4e4a.blogspot.com/2022/01/critical-csrf-in-filebrowser.html
- WEBhttps://febin0x4e4a.wordpress.com/2022/01/19/critical-csrf-in-filebrowser
- WEBhttps://febinj.medium.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7
- WEBhttps://github.com/filebrowser/filebrowser
- WEBhttps://github.com/filebrowser/filebrowser/commit/74b7cd8e81840537a8206317344f118093153e8d
- WEBhttps://github.com/filebrowser/filebrowser/issues/1621
- WEBhttps://pkg.go.dev/vuln/GO-2022-0563
- WEBhttps://systemweakness.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7