Количество 2
Количество 2
CVE-2025-14894
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
GHSA-9g95-48c6-r778
Livewire Filemanager does not restrict uploaded file types
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-14894 Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed. | CVSS3: 7.5 | 0% Низкий | 19 дней назад | |
GHSA-9g95-48c6-r778 Livewire Filemanager does not restrict uploaded file types | CVSS3: 7.5 | 0% Низкий | 19 дней назад |
Уязвимостей на страницу