FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.
References
Configurations
Configuration 1 (hide)
|
History
19 Nov 2024, 15:02
Type | Values Removed | Values Added |
---|---|---|
First Time |
Backpackforlaravel filemanager
Backpackforlaravel |
|
CPE | cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - Patch | |
References | () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - Vendor Advisory |
13 Nov 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-13 16:15
Updated : 2024-11-19 15:02
NVD link : CVE-2024-52306
Mitre link : CVE-2024-52306
JSON object : View
Products Affected
backpackforlaravel
- filemanager
CWE
CWE-502
Deserialization of Untrusted Data