VDB
Sign up
MEDIUM4.5

GHSA-8xfq-7f6m-mpmf

MoonShine Arbitrary File Upload Vulnerability

Quick fix

GHSA-8xfq-7f6m-mpmf — moonshine/moonshine: upgrade to the fixed version with the command below.

composer require moonshine/moonshine:^3.12.5

Details

An arbitrary file upload vulnerability in MoonShine v3.12.4 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moonshine/moonshine
Introduced in: 0Fixed in: 3.12.5
Fixcomposer require moonshine/moonshine:^3.12.5

References