Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g95-48c6-r778

Опубликовано: 16 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Livewire Filemanager does not restrict uploaded file types

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

Пакеты

Наименование

livewire-filemanager/filemanager

composer
Затронутые версииВерсия исправления

<= 1.0.4

Отсутствует

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
19 дней назад

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

CVSS3: 9.8
fstec
19 дней назад

Уязвимость компонента LivewireFilemanagerComponent.php файлового менеджера Livewire Filemanager, позволяющая нарушителю выполнить пролизвольный код

EPSS

Процентиль: 12%
0.00039
Низкий

7.5 High

CVSS3

Дефекты

CWE-434