PT-2022-28182 · Laravel · Laravel Translation Manager

Published

2022-03-18

·

Updated

2022-03-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Laravel Translation Manager versions prior to 0.6.2
Description The issue arises from the lack of validation on locale names, allowing directory traversal when exporting files. This could lead to denial of service. To exploit this, an attacker would need access to the Laravel Translation Manager, as they would have to add and publish a new locale.
Recommendations For versions prior to 0.6.2, update to version 0.6.2 to resolve the issue. As a temporary workaround, consider restricting access to publish and edit translations to only trusted administrators.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-3FVF-2GP4-89WQ

Affected Products

Laravel Translation Manager