Vulnerability Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-force attack to retrieve the passwords of all accounts in a given instance. This issue has been patched in version 2.34.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Filebrowser | Filebrowser | < 2.34.1 |
Related Weaknesses (CWE)
References
- https://github.com/filebrowser/filebrowser/commit/bf37f88c32222ad9c186482bb97338Patch
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-cm2r-rg7r-p7ExploitVendor Advisory
- https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250327-01_F
FAQ
What is CVE-2025-52997?
CVE-2025-52997 is a vulnerability with a CVSS score of 5.9 (MEDIUM). File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy an...
How severe is CVE-2025-52997?
CVE-2025-52997 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52997?
Check the references section above for vendor advisories and patch information. Affected products include: Filebrowser Filebrowser.