CVE-2023-24249: Malicious File Upload
Published Feb 27, 2023
·Updated
An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
1 affected component
laravel-admin laravel-admin=1.8.19
Event History
Feb 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24249?
CVE-2023-24249 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2023-24249?
To fix CVE-2023-24249, update laravel-admin to version 1.8.20 or later where the vulnerability is patched.
3
What software is affected by CVE-2023-24249?
CVE-2023-24249 specifically affects laravel-admin version 1.8.19.
4
What kind of attack is possible with CVE-2023-24249?
CVE-2023-24249 allows attackers to upload malicious PHP files, leading to arbitrary code execution on the server.
5
Is CVE-2023-24249 exploitable remotely?
Yes, CVE-2023-24249 can be exploited remotely if an attacker has access to the file upload functionality of the vulnerable application.