Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23814

Опубликовано: 17 дек. 2021
Источник: nvd
CVSS3: 6.7
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading.

An attacker may be able to reproduce the following steps:

  1. Install a package with a web Laravel application.
  2. Navigate to the Upload window
  3. Upload an image file, then capture the request
  4. Edit the request contents with a malicious file (webshell)
  5. Enter the path of file uploaded on URL - Remote Code Execution

Note: Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Corresponding document can be found in here.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:unisharp:laravel-filemanager:*:*:*:*:*:*:*:*
Версия от 0.0.0 (включая)

EPSS

Процентиль: 84%
0.02089
Низкий

6.7 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-94
CWE-434

Связанные уязвимости

CVSS3: 6.7
github
около 4 лет назад

Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager

EPSS

Процентиль: 84%
0.02089
Низкий

6.7 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-94
CWE-434