{"id":"GHSA-9r2j-rg24-fvpj","summary":"FrozenNode Laravel-Administrator unrestricted file upload","details":"FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via `admin/tips_image/image/file_upload` image upload with PHP content within a GIF image that has the `.php` extension. NOTE: this product is discontinued.","aliases":["CVE-2020-10963"],"modified":"2024-04-23T23:11:43.262853Z","published":"2022-05-24T17:12:48Z","database_specific":{"cwe_ids":["CWE-434"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-23T22:39:50Z","nvd_published_at":"2020-03-25T22:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-10963"},{"type":"WEB","url":"https://xavibel.com/2020/03/23/unrestricted-file-upload-in-frozennode-laravel-administrator"},{"type":"WEB","url":"http://packetstormsecurity.com/files/160243/Laravel-Administrator-4-File-Upload.html"}],"affected":[{"package":{"name":"frozennode/administrator","ecosystem":"Packagist","purl":"pkg:composer/frozennode/administrator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.0.12"}]}],"versions":["4.16.2","v4.0.0","v4.0.1","v4.1.0","v4.10.0","v4.11.0","v4.11.1","v4.11.2","v4.12.0","v4.12.1","v4.13.0","v4.14.0","v4.14.1","v4.14.2","v4.15.0","v4.16.0","v4.16.1","v4.16.3","v4.16.4","v4.16.5","v4.16.6","v4.16.7","v4.17","v4.2.0","v4.3.0","v4.4.0","v4.4.1","v4.5.0","v4.6.0","v4.6.1","v4.7.0","v4.7.1","v4.7.2","v4.8.0","v4.9.0","v5.0.0","v5.0.1","v5.0.10","v5.0.11","v5.0.12","v5.0.2","v5.0.3","v5.0.4","v5.0.5","v5.0.6","v5.0.7","v5.0.8","v5.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9r2j-rg24-fvpj/GHSA-9r2j-rg24-fvpj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}