Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint
High severity
GitHub Reviewed
Published
Aug 12, 2024
in
pxlrbt/filament-excel
•
Updated Sep 16, 2024
Package
Affected versions
>= 2.0.0-alpha, < 2.3.3
< 1.1.14
Patched versions
2.3.3
1.1.14
Description
Published by the National Vulnerability Database
Aug 12, 2024
Published to the GitHub Advisory Database
Aug 12, 2024
Reviewed
Aug 12, 2024
Last updated
Sep 16, 2024
Impact
The export download route
/filament-excel/{path}
allowed downloading any file without login when the webserver allows../
in the URL.Patches
Patched with Version v2.3.3
Credits
Thanks to Kevin Pohl for reporting this.
References