Support the ongoing development of Laravel.io →
Laravel Security

Hackers have been able to upload malicious files via our Laravel application. After analysis we identified that there is a vulnerabilty in the Laravel filemanager. Patches found did not resolve the problem.

Here is a video describing the exploit. https://www.youtube.com/watch?v=hGMuUjOmnU8

Does anybody know of a fix for this security issue?

Thanks.

0

I'm thinking you already saw https://unisharp.github.io/laravel-filemanager/security

They don't have a specific way to report security vulnerabilities so if this is still an issue try opening an issue on their repo to ask to which email address you can report the vulnerability. It's always better to discuss these things in private with the maintainers instead of disclosing these publicly: https://github.com/UniSharp/laravel-filemanager

0

Sign in to participate in this thread!

Eventy

Your banner here too?

Moderators

We'd like to thank these amazing companies for supporting us

Your logo here?

Laravel.io

The Laravel portal for problem solving, knowledge sharing and community building.

© 2025 Laravel.io - All rights reserved.