File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 26 Jun 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue. | |
Title | File Browser has Stored Cross-Site Scripting vulnerability | |
Weaknesses | CWE-79 CWE-80 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-26T14:37:45.905Z
Updated: 2025-06-26T15:01:19.861Z
Reserved: 2025-06-20T17:42:25.712Z
Link: CVE-2025-52902

Updated: 2025-06-26T15:01:12.409Z

Status : Awaiting Analysis
Published: 2025-06-26T15:15:23.687
Modified: 2025-06-26T18:57:43.670
Link: CVE-2025-52902

No data.