Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
References
Configurations
Configuration 1 (hide)
|
History
18 Sep 2024, 18:31
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-22 |
16 Sep 2024, 19:40
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Pxlrbt
Pxlrbt filament Excel |
|
| References | () https://github.com/pxlrbt/filament-excel/commit/bda42891a4b0c15d5dab5da8c53a006ddadccfb7 - Patch | |
| References | () https://github.com/pxlrbt/filament-excel/security/advisories/GHSA-m3px-vjxr-fx4m - Vendor Advisory | |
| CPE | cpe:2.3:a:pxlrbt:filament_excel:*:*:*:*:*:*:*:* |
12 Aug 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-08-12 16:15
Updated : 2024-09-18 18:31
NVD link : CVE-2024-42485
Mitre link : CVE-2024-42485
JSON object : View
Products Affected
pxlrbt
- filament_excel
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
