FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.
References
Configurations
Configuration 1 (hide)
|
History
19 Nov 2024, 15:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:backpackforlaravel:filemanager:*:*:*:*:*:*:*:* | |
Summary |
|
|
References | () https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b - Patch | |
References | () https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2 - Vendor Advisory | |
First Time |
Backpackforlaravel
Backpackforlaravel filemanager |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
13 Nov 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-13 16:15
Updated : 2024-11-19 15:02
NVD link : CVE-2024-52306
Mitre link : CVE-2024-52306
CVE.ORG link : CVE-2024-52306
JSON object : View
Products Affected
backpackforlaravel
- filemanager
CWE
CWE-502
Deserialization of Untrusted Data