SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Vulnerability Overview The Command Execution feature of Filebrowser only allows the execution of shell command which have been predefined on a user-specific allowlist. Many tools allow the execution of arbitrary different commands, rendering this limitation void. Recommended Countermeasure We recommend to disable the… Read More
Vulnerability Overview The Markdown preview function of Filebrowser v2.32.0 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Recommended Countermeasure We recommend to update to Filebrowser version 2.33.7… Read More
Vulnerability Overview URLs that are accessed by a user are commonly logged in many locations, both server- and client-side. It is thus good practice to never transmit any secret information as part of a URL. Filebrowser violates this practice, since access tokens are used as GET parameters. Read More
Vulnerability Overview The file access permissions for files uploaded to or created from Filebrowser are never explicitly set by the application. The same is true for the database used by Filebrowser. On standard servers where the umask configuration has not been hardened before, this makes all the stated files readable… Read More
Our colleague Bernhard Garn, researcher at SBA Research, gave a talk on "Improving the Security of Quantum Platforms using Combinatorial Methods" at the Workshop on Secure Protocol Implementations in the Quantum Era (SPIQE) on June 24th, in Munich, Germany. ... Read More
Our colleagues Philip König, Sebastian Raubitzek, Dennis Toth, Fabian Obermann and Kevin Mallinger published a new paper on Boost-Classifier-Driven Fault Prediction Across Heterogeneous Open-Source Repositories. In this paper they analyzed over 2.4 million commits from 33 open-source projects… Read More
A group of dedicated young researchers presented their work at the 21st ICT Security Conference on 25 and 26 June 2025, which was organized by the Austrian Armed Forces. They impressed the audience with their… Read More
On June 17, SBA Research and its partner Condignum hosted the second edition of the sec4dev Dialogues event series. Security for Software Developers is essential. The current threat landscape and security incidents in recent years make it clear: the topic is more relevant than ever. This… Read More
Cyberduck and Mountain Duck improper handle TLS certificate pinning for
untrusted certificates (e.g., self-signed), since the certificate's
fingerprint is stored as SHA-1, although SHA-1 is considered weak and
should be replaced with SHA-256 or SHA-512. ... Read More
Cyberduck and Mountain Duck improper handle TLS certificate pinning for
untrusted certificates (e.g., self-signed), unnecessary installing it to the
Windows Certificate Store of the current user without any restrictions.
This potentially allows attackers to bypass certificate-based authentication
or authorization of other programs that trust this certificate store. ... Read More
From September 19 to 21, around 65 talented and curious women and FINTA* immersed themselves in the exciting world of cybersecurity at the University of Vienna. This continuing education and networking program is unique in Europe and is designed to make it easier to enter and advance in IT security. ... ∞
The 20th International Conference on Availability, Reliability, and Security (ARES 2025) took center stage in Ghent, Belgium, from August 11-14, 2025, offering a platform for experts and enthusiasts to explore the latest developments in the field. Co-located with ARES 2025 was the 8th International Symposium for Industrial Control System & SCADA Cyber Security Research.... ∞