Remote code execution via special-character file extension
Published Dec 18, 2024 · Updated Aug 28, 2025
Code injection in UniSharp Laravel Filemanager before 2.9.1 allows remote attackers to execute PHP code through a crafted file upload. LfmUploadValidator trusts a client-supplied extension containing special characters, allowing a valid MIME type with a dot after the php suffix to evade executable-extension filtering. Exploitation requires a network-reachable upload route; UniSharp states that the default route should use working authentication middleware, and successful uploads run with the web application's privileges.
Summary
What happened
Code injection in UniSharp Laravel Filemanager before 2.9.1 allows remote attackers to execute PHP code through a crafted file upload. LfmUploadValidator trusts a client-supplied extension containing special characters, allowing a valid MIME type with a dot after the php suffix to evade executable-extension filtering. Exploitation requires a network-reachable upload route; UniSharp states that the default route should use working authentication middleware, and successful uploads run with the web application's privileges.
The record
- CVE
- CVE-2024-21546
- Published
- Dec 18, 2024
- Updated
- Aug 28, 2025
- Vendor
- UniSharp
- Product
- Laravel Filemanager
- Classifications
- CWE-94, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Dec 18, 2024CVE publishedPublication date reported by the CVE source.
- Aug 28, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <2.9.1
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- CVE-2024-21546 reproduction gistproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo