Description
FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly into filesystem paths without any sanitization. An authenticated user with upload permission can exploit this to write files to arbitrary directories on the server, delete arbitrary directories via the post-assembly cleanup, and probe file/directory existence. This issue has been patched in version 3.10.0.
INFO
Published Date :
2026-03-24T19:14:42.771Z
Last Modified :
2026-03-25T16:20:07.262Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-33329 vulnerability.
| Vendors | Products |
|---|---|
| Error311 |
|
| Filerise |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-33329.