CVE-2023-39612: XSS
A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2023-39612.
What is the severity of CVE-2023-39612?
CVE-2023-39612 has a severity level of critical.
How does the cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 occur?
The cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 occurs when an authenticated attacker interacts with a crafted HTML file or URL.
What is the potential impact of the cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0?
The potential impact of the cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 is privilege escalation to Administrator for an authenticated attacker.
How can I fix the cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0?
To fix the cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0, update to version 2.23.0 or later.