Record summary

CVE-2019-25673 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.0.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBUniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File UploadExploitDB exploitby Mohammad DanishNot analyzed1 file
ExploitDB

PoC details

References

5