CVE-2024-21546

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.

Published 2024-12-18. Last modified 2026-06-17.