UniSharp Laravel Filemanager directory traversal vulnerability
Moderate severity
GitHub Reviewed
Published
Sep 15, 2022
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Description
Published by the National Vulnerability Database
Sep 14, 2022
Published to the GitHub Advisory Database
Sep 15, 2022
Reviewed
Sep 16, 2022
Last updated
Dec 7, 2023
UniSharp laravel-filemanager (aka Laravel Filemanager) with
league/flysystem
version< 2.0.0
allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022.Since
v2.6.4
, UniSharp laravel-filemanager (aka Laravel Filemanager) requires users to installleague/flysystem
version>= 2.0.0
.References