CVE-2024-52306

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*
cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*

History

19 Nov 2024, 15:02

Type Values Removed Values Added
CPE cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:*
Summary
  • (es) FileManager proporciona una interfaz de administración de Backpack para archivos y carpetas. Antes de la versión 3.0.9, la deserialización de datos no confiables del parámetro mimes podía provocar la ejecución remota de código. Esta vulnerabilidad se solucionó en la versión 3.0.9.
References () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - Patch
References () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - Vendor Advisory
First Time Backpackforlaravel
Backpackforlaravel filemanager
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 9.8

13 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-13 16:15

Updated : 2024-11-19 15:02


NVD link : CVE-2024-52306

Mitre link : CVE-2024-52306

CVE.ORG link : CVE-2024-52306


JSON object : View

Products Affected

backpackforlaravel

  • filemanager
CWE
CWE-502

Deserialization of Untrusted Data