What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1.
Explanation of Vulnerability in Simple Terms
02Summary
Smallerik File Browser versions 1.1 and earlier allow authenticated users to upload files without restriction. An attacker with low-level access can upload malicious files to the server, potentially executing code or compromising the entire system. The vulnerability affects confidentiality, integrity, and availability across the application scope.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files on the server, gaining control over the site and its data.
Potential impact on your site
04Site Impact
Complete compromise of the site, data theft, malware injection, and potential lateral movement to other systems.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the application.
Key dates
06Disclosure timeline
January 22, 2025
CVE published
April 28, 2026
Record updated