Deserialization of untrusted data from the mimes parameter could lead to remote code execution.
Fixed in 3.0.9
Not needed, a composer update will solve it in a non-breaking way.
Reported responsibly Vladislav Gladkiy at Positive Technologies.
| Score | Percentile |
|---|---|
| 4.96% | 89.64% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.7 | 3.1 | — |
|
| 8.5 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-8237-957h-h2c2 ↗ |
| CVE | CVE-2024-52306 ↗ |
| CWE id | Name |
|---|---|
| CWE-502 | Deserialization of Untrusted Data |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | backpack/filemanager | >= 3.0.0, < 3.0.9 | 3.0.9 | — |
| composer | backpack/filemanager | < 2.0.2 | 2.0.2 | — |