GHSA-3fvf-2gp4-89wq

    Dashboard / Vulnerabilities / GHSA-3fvf-2gp4-89wq

    GHSA-3fvf-2gp4-89wq

    Published: 18 Mar 2022Last Modified: 5 Dec 2024

    Summary: Possibility for Denial of Service by overwriting PHP files with language exports

    Details: ### Impact Laravel Translation Manager didn't check the locale name, which allowed directory traversal when exporting files. The content would be a PHP file returning an array of translations, but this could lead to unexpected results, like denial of service. Access to the Laravel Translation Manager is required, because a new locale would have to be added and published. ### Patches Version 0.6.2 fixes this issue. ### Workarounds Only allow trusted admins to publish/edit translations. ### References https://github.com/barryvdh/laravel-translation-manager/pull/417 ### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/barryvdh/laravel-translation-manager * Email me (see Github profile) ### Credits Found and reported by [Natalia Trojanowska](https://www.linkedin.com/in/trojanowskanatalia/)

    Affected packages

    Package

    Name: barryvdh/laravel-translation-manager

    Purl: pkg:composer/barryvdh/laravel-translation-manager

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.6.2

    Affected versions

    v0.1.0
    v0.1.1
    v0.1.2
    v0.1.3
    v0.1.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3fvf-2gp4-89wq | CVE-DB