Beveiligingsadvies

CVE-2026-4809

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-26 11:03:27
Laatst bijgewerkt 2026-08-10 11:43:52
Toegewezen door TuranSec
CVSS-score 10.0
Status PUBLISHED

Beschrijving

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.