PT-2026-30482 · Unisharp · Laravel-File-Manager
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UniSharp Laravel File Manager versions 2.0.0-alpha7 through 2.0
Description
Authenticated attackers can upload malicious files by sending multipart form data to the upload endpoint. By setting the
type parameter to 'Files', attackers can upload PHP files and execute arbitrary code by accessing the uploaded file via the working directory path.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laravel-File-Manager