UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
UniSharp · Laravel File Managerpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/46389unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.