Vulnerability Description
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unisharp | Laravel Filemanager | <= 2.5.1 |
Related Weaknesses (CWE)
References
- https://github.com/UniSharp/laravel-filemanager/issues/1150ExploitIssue TrackingThird Party Advisory
- https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1320186
- https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1825310
- https://github.com/UniSharp/laravel-filemanager/issues/1150ExploitIssue TrackingThird Party Advisory
- https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1320186
- https://github.com/UniSharp/laravel-filemanager/issues/1150#issuecomment-1825310
FAQ
What is CVE-2022-40734?
CVE-2022-40734 is a vulnerability with a CVSS score of 6.5 (MEDIUM). UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is relate...
How severe is CVE-2022-40734?
CVE-2022-40734 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40734?
Check the references section above for vendor advisories and patch information. Affected products include: Unisharp Laravel Filemanager.