Record summary

CVE-2022-40734 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 14, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 2.6.4 · Fixed in 2.6.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLaravel Filemanager v2.5.1 - Local File InclusionCVSS 6.5

Laravel Filemanager (aka UniSharp) through version 2.5.1 is vulnerable to local file inclusion via download?working_dir=%2F.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, sensitive data exposure, and remote code execution.

Remediation

Upgrade to a patched version of Laravel Filemanager v2.5.1 or apply the recommended security patches provided by the vendor.

WeaknessesCWE-22
Authorsarafatansari
Template tagscvecve2022laravelunisharplfitraversalvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:unisharp:laravel_filemanager:*:*:*:*:*:*:*:*
Shodan: http.html:"Laravel Filemanager"
Shodan: http.html:"laravel filemanager"
FOFA: body="laravel filemanager"

Source: ProjectDiscovery

References

4