CVE-2025-65346
- EPSS 0.27%
- Veröffentlicht 04.12.2025 15:15:59
- Zuletzt bearbeitet 16.12.2025 18:04:39
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extrac...
CVE-2025-65345
- EPSS 0.03%
- Veröffentlicht 03.12.2025 20:16:26
- Zuletzt bearbeitet 16.12.2025 19:14:09
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.
CVE-2025-63307
- EPSS 0.05%
- Veröffentlicht 06.11.2025 16:16:13
- Zuletzt bearbeitet 08.12.2025 16:14:46
alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation...