CVE Feed

    Dashboard / CVE / CVE-2025-56399

    CVE-2025-56399

    alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file is still saved on the server. The attacker can then use the rename API to change the file extension to `.php`, and upon accessing it via a public URL, the server executes the embedded code.

    Published:Oct 28, 2025
    Last Modified:Apr 15, 2026
    EPS:Oct 28, 2025
    EPSS Score:0.00196
    CVSS Score:8.8

    Affected Products

    Vendor
    Alexusmai
    Product
    Laravel-file-manager
    Vendor
    Laravel
    Product
    Laravel

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High