{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/filerise-pro--3.24.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FileRise Pro (\u003c 3.24.0)"],"_cs_severities":["medium"],"_cs_tags":["information-disclosure","api-security","reconnaissance"],"_cs_type":"advisory","_cs_vendors":["FileRise"],"content_html":"\u003cp\u003eFileRise Pro versions prior to 3.24.0 contain an unauthenticated information disclosure vulnerability within the \u003ccode\u003epublic/api/pro/portals/get.php\u003c/code\u003e endpoint. The vulnerability exists because the endpoint fails to invoke the \u003ccode\u003efr_pro_guard_auth()\u003c/code\u003e authentication check used by sibling endpoints. Consequently, any unauthenticated user who identifies a valid portal slug - a non-secret, human-readable identifier - can query this endpoint to receive a full record of the portal's configuration.\u003c/p\u003e\n\u003cp\u003eExposed data includes the server's internal storage folder path, client contact emails, and detailed upload policy constraints (e.g., file extension whitelists, upload limits). This information provides significant reconnaissance value to an attacker by mapping the application's internal structure and identifying targets for subsequent exploitation attempts against file-handling functionalities. The vendor has released a patch in version 3.24.0, which mandates session-based authentication for this endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application instance running FileRise Pro.\u003c/li\u003e\n\u003cli\u003eAttacker obtains or guesses a valid portal slug (e.g., from public email correspondence or open-source intelligence).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an unauthenticated HTTP GET request to the target URL: \u003ccode\u003ehttps://\u0026lt;target\u0026gt;/api/pro/portals/get.php?slug=\u0026lt;guessed_slug\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application processes the request in \u003ccode\u003ePortalController::getPortalBySlug()\u003c/code\u003e without invoking authentication guards.\u003c/li\u003e\n\u003cli\u003eThe server serializes and returns the complete portal configuration record, including sensitive internal paths and PII.\u003c/li\u003e\n\u003cli\u003eAttacker harvests the disclosed internal storage paths and business policy details.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the reconnaissance data to conduct further probes against file upload or download functionalities within the environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the disclosure of internal metadata, including server-side directory structures, client PII, and security policy details. While the vulnerability does not directly permit remote code execution or file modification, the exposure of internal paths and upload constraints facilitates further reconnaissance and targeted exploitation of the file-processing infrastructure. All FileRise deployments with the Pro add-on configured are affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all FileRise Pro instances to version 3.24.0 or later to ensure the authentication guard is correctly enforced.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous GET requests to \u003ccode\u003epublic/api/pro/portals/get.php\u003c/code\u003e originating from unauthorized or non-standard sources.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for attempts to access internal API endpoints that typically require authentication.\u003c/li\u003e\n\u003cli\u003eEnsure that internal directory structures disclosed by this vulnerability are not used to inform further security hardening or segmentation efforts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:26:56Z","date_published":"2026-10-01T20:26:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-filerise-disclosure/","summary":"An unauthenticated information disclosure vulnerability in the FileRise Pro portal endpoint allows attackers to retrieve sensitive configuration data, including internal storage paths and client contact information.","title":"Unauthenticated Information Disclosure in FileRise Pro","url":"https://feed.craftedsignal.io/briefs/2026-10-filerise-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - FileRise Pro (\u003c 3.24.0)","version":"https://jsonfeed.org/version/1.1"}