A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0...
Vulnerability Description
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-46398
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/filebrowser/filebrowser/commit/74b7cd8e81840537a8206317344f118093153e8d
- https://febin0x4e4a.blogspot.com/2022/01/critical-csrf-in-filebrowser.html
- https://febin0x4e4a.wordpress.com/2022/01/19/critical-csrf-in-filebrowser/
- https://systemweakness.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7
- http://packetstormsecurity.com/files/165885/FileBrowser-2.17.2-Code-Execution-Cross-Site-Request-Forgery.html
- https://febinj.medium.com/critical-csrf-to-rce-in-filebrowser-865a3c34b8e7
More from filebrowser
View All →Affected Vendor
filebrowser
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.