Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kevin Pohl

#30301of 53,630
8.7Total CVSS
Vulnerabilities · 1
PT-2024-29982
8.7
2024-08-12
Unknown · Filament Excel · CVE-2024-42485
**Name of the Vulnerable Software and Affected Versions** Filament Excel versions prior to v2.3.3 **Description** The export download route "/filament-excel/{path}" allowed downloading any file without login when the webserver allows ../ in the URL. This issue was reported by Kevin Pohl. **Recommendations** For versions prior to v2.3.3, update to version v2.3.3 to resolve the issue. As a temporary workaround, consider restricting access to the "/filament-excel/{path}" endpoint until the update is applied.