GHSA-6569-3785-r3v6
GitHub Security Advisory
UniSharp Laravel Filemanager Code Injection vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.
Affected Packages
Packagist
unisharp/laravel-filemanager
Affected versions:
0
(fixed in 2.9.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 13, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.