Intel

AIKIDO-2024-10454

backpack/filemanager is vulnerable to Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 20, 2024

61

Medium Risk

This Affects:

phpbackpack/filemanager
1.1.3 - 3.0.9
Fixed in 3.0.10
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow users to tamper with the MIME type of files they upload, enabling the upload of files with dangerous types. This vulnerability could potentially lead to Remote Code Execution (RCE) or other security threats.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

backpack/filemanager is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 1.1.3 - 3.0.9.

How to fix this

Upgrade the backpack/filemanager library to the patch version.