z-song / laravel-admin

Build a full-featured administrative interface in ten minutes
https://laravel-admin.org
MIT License
11.15k stars 2.82k forks source link

Vulnerability Fixes #5764

Open OneWalkDev opened 1 year ago

OneWalkDev commented 1 year ago

Description:

https://github.com/advisories/GHSA-g857-47pm-3r32

An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.

Steps To Reproduce: