CVE 7.1 HIGH

FileRise ONLYOFFICE integration allows read-only users to overwrite files via forged save callback_CVE-2026-33330

7.1 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Description

FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite that file with attacker-controlled content. This issue has been patched in version 3.10.0.

Basic Information

ID CVE-2026-33330
Source GitHub_M
Published Mar 24, 2026 at 19:15
Modified Mar 24, 2026 at 20:07

Affected Product

Vendor error311
Product FileRise
Version < 3.10.0
Affected Versions error311 FileRise < 3.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.