CVE-2025-52996 Details
Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file through a direct download link. This link can either be shared unknowingly by a user or discovered from various locations such as the browser history or the log of a proxy server used. At time of publication, no known patched versions are available.
A vulnerability exists in File Browser versions through 2.32.0, allowing for unprotected sharing of files via direct download links. The issue arises from an error-prone implementation of password protection for shared links. Users can inadvertently share unprotected links, which can be accessed by anyone with the link, potentially leading to unauthorized download of sensitive files.
Users should be cautious when sharing files and ensure that the correct link is used. File Browser has released a version 2.34.2 to mitigate user error by removing the unprotected download link from the sharing interface. However, this does not address the unprotected links that may already exist in logs or browser history.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-305 | Authentication Bypass by Primary Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| filebrowser filebrowser | <= 2.32.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | CVE Modified | [email protected] |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| Jun 30, 2025 | New CVE Received | [email protected] |