Insecure Authentication in File Browser Allows Brute-Force Attacks
CVE-2025-52997
5.9MEDIUM
What is CVE-2025-52997?
File Browser, a file management tool, has a vulnerability that arises from a lack of a robust password policy and inadequate brute-force attack protection. This weakness allows attackers to potentially perform brute-force attacks, thereby compromising user accounts by retrieving passwords across an instance. The issue has been resolved in version 2.34.1 where enhanced authentication security measures have been implemented.
Affected Version(s)
filebrowser < 2.34.1