AI description
CVE-2025-56399 is a Remote Code Execution (RCE) vulnerability found in versions 3.3.1 and earlier of the `alexusmai/laravel-file-manager` package. This flaw allows an authenticated attacker to execute arbitrary PHP code on the server. The vulnerability is exploited by uploading a crafted file, such as one with a `.png` extension containing PHP code, through the file manager interface. Despite client-side validation potentially indicating a failed upload, the file is still saved on the server. The attacker can then leverage the package's rename API to change the file's extension to `.php`, leading to the execution of the embedded code when accessed via a public URL.
- Description
- alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file is still saved on the server. The attacker can then use the rename API to change the file extension to `.php`, and upon accessing it via a public URL, the server executes the embedded code.
- Source
- cve@mitre.org
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
6
#CVE-2025-56399 — #Laravel File Manager Unrestricted Upload Authenticated #RCE via File Upload + Rename This is a **two-step attack**: 1. Upload payload disguised as image → saved server-side 2. Rename extension to `.php` → RCE on access #security #0days #exploit #hacking
@YogSoth0
28 Jun 2026
2707 Impressions
11 Retweets
54 Likes
31 Bookmarks
2 Replies
0 Quotes
CVE-2025-56399 alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '… https://t.co/vPQkeAX5gQ
@CVEnew
28 Oct 2025
216 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes