CVE-2024-52306

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*
cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*

History

19 Nov 2024, 15:02

Type Values Removed Values Added
First Time Backpackforlaravel filemanager
Backpackforlaravel
CPE cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - Patch
References () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - Vendor Advisory

13 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 16:15

Updated : 2024-11-19 15:02


NVD link : CVE-2024-52306

Mitre link : CVE-2024-52306


JSON object : View

Products Affected

backpackforlaravel

  • filemanager
CWE
CWE-502

Deserialization of Untrusted Data