CVE-2024-52306

HIGH

FileManager <3.0.9 - Code Injection

Title source: llm
STIX 2.1

Description

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.

Scores

CVSS v3 7.6
EPSS 0.0057
EPSS Percentile 42.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
backpack/filemanager 3.0.0 - 3.0.9Packagist
backpackforlaravel/filemanager < 2.0.2
Published Nov 13, 2024
Tracked Since Feb 18, 2026