PT-2026-30482 · Unisharp · Laravel-File-Manager

·

CVE-2019-25673

·

Published

2026-04-05

·

Updated

2026-04-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UniSharp Laravel File Manager versions 2.0.0-alpha7 through 2.0
Description Authenticated attackers can upload malicious files by sending multipart form data to the upload endpoint. By setting the type parameter to 'Files', attackers can upload PHP files and execute arbitrary code by accessing the uploaded file via the working directory path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25673

Affected Products

Laravel-File-Manager