CRITICAL9.8
GHSA-6569-3785-r3v6
UniSharp Laravel Filemanager Code Injection vulnerability
Quick fix
GHSA-6569-3785-r3v6 — unisharp/laravel-filemanager: upgrade to the fixed version with the command below.
composer require unisharp/laravel-filemanager:^2.9.1Details
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/unisharp/laravel-filemanager
Introduced in:
0Fixed in: 2.9.1Fix
composer require unisharp/laravel-filemanager:^2.9.1References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21546[ADVISORY]
- https://github.com/UniSharp/laravel-filemanager/commit/8170760c0ae316d77b9363cd4c76ab68d3f63f0b[WEB]
- https://gist.github.com/ImHades101/338a06816ef97262ba632af9c78b78ca[WEB]
- https://github.com/UniSharp/laravel-filemanager[PACKAGE]
- https://security.snyk.io/vuln/SNYK-PHP-UNISHARPLARAVELFILEMANAGER-7210316[WEB]