Ad

CVE-2026-33477

MEDIUM CVSS 3.1: 4.3 EPSS 0.03%
Updated Mar 31, 2026
Filerise
Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions 2.3.7 — 3.11.0
Fixed In 3.11.0
Type CWE-863 (Incorrect Authorization)
Vendor Filerise
Public PoC No

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a folder to retrieve snippet content from files uploaded by other users in the same folder. This is a server-side authorization flaw in the `read_own` enforcement for hover previews.

Version 3.11.0 fixes the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Filerise Filerise
cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:*
2.3.7 3.11.0