CVE-2025-14894 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, al…
Critical CVSS: 9.8

CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.
Vendor
Livewire-filemanager
Product
Filemanager
CWE
CWE-434
Yayın Tarihi
2026-01-16 13:16:11
Güncelleme
2026-01-23 17:04:25
Source Identifier
cret@cert.org
KEV Date Added
-

Kategoriler

Referanslar