FileRise File Manager Vulnerability Allowing Unauthorized Folder Access
CVE-2025-62510
What is CVE-2025-62510?
In version 1.4.0 of FileRise, a self-hosted web-based file manager, an access control misconfiguration allowed low-privilege users to infer folder visibility based on folder names. This vulnerability enabled users to see or potentially interact with folders that matched their usernames, and in certain scenarios, access the content of other users. The issue has been resolved in version 1.5.0, which implements explicit per-folder access control lists (ACLs) and enhances server-side checks across various file-related operations, reinforcing data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FileRise = 1.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
