Official Product Homepageproduct
https://github.com/UniSharp/laravel-filemanager CVE-2019-25673
HIGH
UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload
Record summary
CVE-2019-25673 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Laravel File ManagerBrowse UniSharp / Laravel File Manager | CVE List | 2.0.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBUniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File UploadExploitDB exploitby Mohammad DanishNot analyzed1 file
References
5Source Code Repositoryissue tracking
https://github.com/UniSharp/laravel-filemanager/issues/356 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25673 ExploitDB-46389exploit
https://www.exploit-db.com/exploits/46389 VulnCheck Advisory: UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File UploadThird-party advisory
https://www.vulncheck.com/advisories/unisharp-laravel-file-manager-alpha7-arbitrary-file-upload