Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m2h-7rf2-rpx6

Опубликовано: 15 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

UniSharp Laravel Filemanager directory traversal vulnerability

UniSharp laravel-filemanager (aka Laravel Filemanager) with league/flysystem version < 2.0.0 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022.

Since v2.6.4, UniSharp laravel-filemanager (aka Laravel Filemanager) requires users to install league/flysystem version >= 2.0.0.

Пакеты

Наименование

unisharp/laravel-filemanager

composer
Затронутые версииВерсия исправления

< 2.6.4

2.6.4

EPSS

Процентиль: 100%
0.92943
Критический

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.

EPSS

Процентиль: 100%
0.92943
Критический

6.5 Medium

CVSS3

Дефекты

CWE-22