ID:6964 - Exploit for Arbitrary file upload in Laravel-Administrator - CVE-2020-10963

 
Main Vulnerability Database Exploits ID:6964 - Exploit for Arbitrary file upload in Laravel-Administrator - CVE-2020-10963

ID:6964 - Exploit for Arbitrary file upload in Laravel-Administrator - CVE-2020-10963

Published: November 1, 2021


Vulnerability identifier: #VU26641
Vulnerability risk: Medium
CVE-ID: CVE-2020-10963
CWE-ID: CWE-434
Exploitation vector: Remote access
Vulnerable software:
Laravel-Administrator

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to improper input validation. A remote administrator can upload and execute arbitrary file on the target system via "admin/tips_image/image/file_upload" image upload with PHP content within a GIF image that has the .php extension.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.