<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:01:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00103</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00103</link>
      <description>bdu:2026-00103</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00103</guid>
    </item>
    <item>
      <title>cnvd-2025-22703</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-22703</link>
      <description>cnvd-2025-22703</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-22703</guid>
    </item>
    <item>
      <title>EUVD-2026-248971</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248971</link>
      <description>EUVD-2026-248971</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248971</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52996</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52996</link>
      <description>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file through a direct download link. This link can either be shared unknowingly by a user or discovered from various locations such as the browser history or the log of a proxy server used. At time of publication, no known patched versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected sharing of a file through a direct download link. This link can either be shared unknowingly by a user or discovered from various locations such as the browser history or the log of a proxy server used. At time of publication, no known patched versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52996</guid>
    </item>
    <item>
      <title>GHSA-3v48-283x-f2w4 — File Browser's password protection of links is bypassable</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3v48-283x-f2w4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;Files managed by the *File Browser* can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible.&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;File owners might rest in the assumption that their shared files are only accessible to persons knowing the defined password, giving them a false sense of security. Meanwhile, attackers gaining access to the unprotected link can use this information alone to download the possibly sensitive file.&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;When sharing a file, the user is presented with a dialog asking for an optional password to protect the file share. The assumption of the user at this point would be, that the shared file won&amp;#39;t be accessible without knowledge of the password. After clicking on `SHARE` the following dialog opens allowing the file&amp;#39;s owner to copy the share-link:&lt;/p&gt;
&lt;p&gt;![image](https://github.com/user-attachments/assets/f3add074-40ac-4367-a538-ede5bb526916)&lt;/p&gt;
&lt;p&gt;In fact, there is not one, but two links offered: A `Download Link` and an unnamed second one. They have the following format:&lt;/p&gt;
&lt;p&gt;* http://filebrowser.local:8080/share/6Gtw0xAw
* http://filebrowser.local:8080/api/public/dl/6Gtw0xAw/dummy1.pdf?token=voDK6j[...]&lt;/p&gt;
&lt;p&gt;Apparently, the first of the two share links is that one that users are supposed to actually share, while the second one is a direct download link not protected by the password. This behavior…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;## Summary ##&lt;/p&gt;
&lt;p&gt;Files managed by the *File Browser* can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible.&lt;/p&gt;
&lt;p&gt;## Impact ##&lt;/p&gt;
&lt;p&gt;File owners might rest in the assumption that their shared files are only accessible to persons knowing the defined password, giving them a false sense of security. Meanwhile, attackers gaining access to the unprotected link can use this information alone to download the possibly sensitive file.&lt;/p&gt;
&lt;p&gt;## Vulnerability Description ##&lt;/p&gt;
&lt;p&gt;When sharing a file, the user is presented with a dialog asking for an optional password to protect the file share. The assumption of the user at this point would be, that the shared file won&amp;#39;t be accessible without knowledge of the password. After clicking on `SHARE` the following dialog opens allowing the file&amp;#39;s owner to copy the share-link:&lt;/p&gt;
&lt;p&gt;![image](https://github.com/user-attachments/assets/f3add074-40ac-4367-a538-ede5bb526916)&lt;/p&gt;
&lt;p&gt;In fact, there is not one, but two links offered: A `Download Link` and an unnamed second one. They have the following format:&lt;/p&gt;
&lt;p&gt;* http://filebrowser.local:8080/share/6Gtw0xAw
* http://filebrowser.local:8080/api/public/dl/6Gtw0xAw/dummy1.pdf?token=voDK6j[...]&lt;/p&gt;
&lt;p&gt;Apparently, the first of the two share links is that one that users are supposed to actually share, while the second one is a direct download link not protected by the password. This behavior…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3v48-283x-f2w4</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
