top of page
perceptive_background_267k.jpg

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a …

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

FileRise, a self-hosted web-based file manager, has a critical vulnerability in versions prior to 3.12.0. The /api/totp_setup.php endpoint improperly handles TOTP configuration requests from sessions that have only passed password authentication. When a user account already has TOTP configured, the endpoint incorrectly decrypts and returns the existing TOTP secret within a QR PNG response. This allows attackers who possess a victim's password to extract the live TOTP secret, generate valid one-time codes, and bypass two-factor authentication to gain full session access without physical access to the victim's authenticator device. The vulnerability represents a complete bypass of multi-factor authentication protections and has been fixed in version 3.12.0.

Technical details

Mitigation steps:

Affected products:

FileRise

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page