Логотип exploitDog
bind:CVE-2025-63307
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-63307

Количество 2

Количество 2

nvd логотип

CVE-2025-63307

3 месяца назад

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-f9mp-xcq7-hf3m

3 месяца назад

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-63307

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-f9mp-xcq7-hf3m

alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

0%
Низкий
3 месяца назад

Уязвимостей на страницу