A Cross-Site Request Forgery vulnerability exists in Filebrowser that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0563" }