unisharp CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

unisharp vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to unisharp, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-40734 UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0. [email protected] 6.5 91.65% 2022-09-14 2024-11-21
CVE-2021-23814 This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** P [email protected] 6.7 2.09% 2021-12-17 2025-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence