
An authenticated Directory Traversal vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager interface to use zip/archiving function to create archives containing files and directories outside the intended scope due to improper path validation.
An authenticated Directory Traversal vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager interface to use zip/archiving function to create archives containing files and directories outside the intended scope due to improper path validation.
laravel-file-manager💥 Impact
🛡️ Recommended Remediation
🙏 Credits
Discovered and reported by: Chindanai Klabtung, Chayawat Jeamprasertboon, Thanakorn Boontem, Theethat Thamwasin