Логотип exploitDog
bind:CVE-2025-14894
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14894

Количество 2

Количество 2

nvd логотип

CVE-2025-14894

19 дней назад

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9g95-48c6-r778

19 дней назад

Livewire Filemanager does not restrict uploaded file types

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

CVSS3: 7.5
0%
Низкий
19 дней назад
github логотип
GHSA-9g95-48c6-r778

Livewire Filemanager does not restrict uploaded file types

CVSS3: 7.5
0%
Низкий
19 дней назад

Уязвимостей на страницу