VDB
Sign up
CRITICAL9.8

GHSA-m5hw-rhvr-f47c

simogeo/filemanager arbitrary file upload vulnerability

Details

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/simogeo/filemanager
Introduced in: 0

No fixed version published yet for simogeo/filemanager (composer). Pin to a known-safe version or switch to an alternative.

References