Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9mp-xcq7-hf3m

Опубликовано: 06 нояб. 2025
Источник: github
Github: Не прошло ревью

Описание

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

EPSS

Процентиль: 15%
0.00049
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

EPSS

Процентиль: 15%
0.00049
Низкий