PT-2026-99146 · Laranode · Laranode
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Laranode versions prior to 1.2.1
Description
Authenticated users can perform a path traversal attack via the 'POST /filemanager/upload-file' endpoint. By providing directory traversal sequences in the
path parameter, an attacker can write arbitrary files, such as PHP files, outside their designated home directory and into the web roots of other tenants, leading to remote code execution within those tenants' contexts.Recommendations
Update Laranode to version 1.2.1 or later.
As a temporary mitigation, restrict access to the 'POST /filemanager/upload-file' endpoint or avoid using the
path parameter until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Laranode