An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
References
Link | Resource |
---|---|
https://github.com/z-song/laravel-admin | Product |
https://flyd.uk/post/cve-2023-24249/ | Exploit Third Party Advisory |
https://laravel-admin.org/ | Product |
Configurations
Information
Published : 2023-02-27 11:15
Updated : 2023-03-07 11:47
NVD link : CVE-2023-24249
Mitre link : CVE-2023-24249
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
laravel-admin
- laravel-admin