CVE-2024-21546
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 18, 2024
CWE ID 94
Summary
CVE-2024-21546 is a Remote Code Execution (RCE) vulnerability affecting versions of the unisharp/laravel-filemanager package before 2.9.1. An attacker can exploit this flaw by providing a valid mimetype and inserting a dot (.) after the php file extension, enabling the execution of malicious code. This vulnerability poses a significant risk and can lead to serious consequences if exploited. It is recommended that users of the unisharp/laravel-filemanager package update to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.