UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 92% probability of exploitation within the next 30 days (top 0.3% of all CVEs). NVD baseline CVSS 6.5 retained for reference. Confidence: see factors.
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.
September 14, 2022
November 21, 2024
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| unisharp/laravel-filemanager | 0.1.0 ... v2.6.3 (65 versions) | 2.6.4 | — |
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-40734
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.