Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
References
Configurations
Configuration 1 (hide)
|
History
16 Sep 2024, 19:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pxlrbt/filament-excel/commit/bda42891a4b0c15d5dab5da8c53a006ddadccfb7 - Patch | |
References | () https://github.com/pxlrbt/filament-excel/security/advisories/GHSA-m3px-vjxr-fx4m - Vendor Advisory | |
First Time |
Pxlrbt
Pxlrbt filament Excel |
|
Summary |
|
|
CPE | cpe:2.3:a:pxlrbt:filament_excel:*:*:*:*:*:*:*:* |
12 Aug 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-12 16:15
Updated : 2024-09-18 18:31
NVD link : CVE-2024-42485
Mitre link : CVE-2024-42485
CVE.ORG link : CVE-2024-42485
JSON object : View
Products Affected
pxlrbt
- filament_excel
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')