CVE-2021-45040: Malicious File Upload
Published Mar 17, 2022
·Updated
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
Affected Software
2 affected components
spatie Laravel Media Library<=1.17.10
spatie Laravel Media Library>=2.0.0<=2.1.6
Event History
Mar 17, 2022
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-45040?
CVE-2021-45040 has a medium severity rating due to the potential for remote code execution through file uploads.
2
How do I fix CVE-2021-45040?
To fix CVE-2021-45040, upgrade the Spatie media-library-pro library to version 1.17.11 or 2.1.7 or later.
3
What types of files can be uploaded due to CVE-2021-45040?
CVE-2021-45040 allows attackers to upload executable files that could be potentially harmful.
4
Which versions of Spatie Laravel Media Library are affected by CVE-2021-45040?
CVE-2021-45040 affects Spatie Laravel Media Library versions up to 1.17.10 and from 2.0.0 to 2.1.6.
5
Who is impacted by CVE-2021-45040?
Any Laravel application using the affected versions of the Spatie media-library-pro library is vulnerable to CVE-2021-45040.