id: CVE-2026-25231 info: name: FileRise <= 3.3.0 - Unauthenticated File Read author: str4k3r severity: high description: | FileRise <= 3.3.0 contains an unauthenticated file read vulnerability caused by a lack of access control on the /uploads directory, letting unauthenticated attackers access uploaded files directly, exploit requires knowledge or guessing of file paths. impact: | Unauthenticated attackers can access sensitive uploaded files, leading to data exposure and privacy breaches. remediation: | Upgrade to version 3.3.0 or later. reference: - https://github.com/error311/FileRise/security/advisories/GHSA-hv99-77cw-hvpr - https://github.com/error311/FileRise classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cwe-id: CWE-284 metadata: verified: true max-request: 3 vendor: error311 product: filerise shodan-query: 'http.title:"FileRise"' fofa-query: 'title="FileRise"' google-query: 'intitle:"FileRise"' tags: cve,cve2026,filerise,exposure,file-read flow: http(1) && (http(2) || http(3)) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 2 matchers: - type: dsl dsl: - "status_code == 200" - "contains(to_lower(body), '