CVE-2020-10963: Frozennode Laravel-Administrator

High severity, CVSS 7.2. EPSS: 14.7% chance of exploitation in the next 30 days.

FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

Affected products

  • Frozennode Laravel-Administrator: up to and including 5.0.12

Published 2020-03-25. Last modified 2026-06-17.