PT-2026-48811 · Filamentphp+2 · Filament+2
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
filament/actions versions 4.0.0 through 4.11.3
filament/actions versions 5.0.0 through 5.6.3
filament/tables versions 3.0.0 through 3.3.50
Description
The
recordSelectOptionsQuery() method is used to scope options available in the Select field for AttachAction and AssociateAction. Because the built-in validation rule for these fields failed to apply the same scope, a user capable of triggering these actions could tamper with the Livewire component state to submit a value that falls outside the intended scope.Recommendations
Update filament/actions to version 4.11.4 or 5.6.4.
Update filament/tables to version 3.3.51.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filament
Filament/Actions
Filament/Tables