An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://laravel-admin.org/ | product |
https://github.com/z-song/laravel-admin | product |
https://flyd.uk/post/cve-2023-24249/ | third party advisory exploit |