MEDIUM4.5
GHSA-8xfq-7f6m-mpmf
MoonShine Arbitrary File Upload Vulnerability
Quick fix
GHSA-8xfq-7f6m-mpmf — moonshine/moonshine: upgrade to the fixed version with the command below.
composer require moonshine/moonshine:^3.12.5Details
An arbitrary file upload vulnerability in MoonShine v3.12.4 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/moonshine/moonshine
Introduced in:
0Fixed in: 3.12.5Fix
composer require moonshine/moonshine:^3.12.5