Intel

AIKIDO-2024-10189

spatie/laravel-medialibrary is vulnerable to Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

85

High Risk

This Affects:

PHPspatie/laravel-medialibrary
8.0.0 - 11.7.3
Fixed in 11.7.4

TL;DR

Affected versions of the package allow attackers to upload media files that appear to be PHP files after sanitizing the filename.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spatie/laravel-medialibrary is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 8.0.0 - 11.7.3.

How to fix this

Upgrade the spatie/laravel-medialibrary library to the patch version.