CVE-2020-10963: Frozennode Laravel-Administrator
High severity, CVSS 7.2. EPSS: 14.7% chance of exploitation in the next 30 days.
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.
Affected products
- Frozennode Laravel-Administrator: up to and including 5.0.12
Published 2020-03-25. Last modified 2026-06-17.