CVE-2025-65345
MEDIUMAlexusmai Laravel File Manager < 3.3.1 - Path Traversal
Title source: ruleDescription
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0003
EPSS Percentile
10.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-22
Status
published
Products (2)
alexusmai/laravel-file-manager
0Packagist
alexusmai/laravel_file_manager
< 3.3.1
Published
Dec 03, 2025
Tracked Since
Feb 18, 2026