PT-2022-28182 · Laravel · Laravel Translation Manager
Published
2022-03-18
·
Updated
2022-03-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Laravel Translation Manager versions prior to 0.6.2
Description
The issue arises from the lack of validation on locale names, allowing directory traversal when exporting files. This could lead to denial of service. To exploit this, an attacker would need access to the Laravel Translation Manager, as they would have to add and publish a new locale.
Recommendations
For versions prior to 0.6.2, update to version 0.6.2 to resolve the issue.
As a temporary workaround, consider restricting access to publish and edit translations to only trusted administrators.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Laravel Translation Manager