Headline
GHSA-m3px-vjxr-fx4m: Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint
Impact
The export download route /filament-excel/{path}
allowed downloading any file without login when the webserver allows ../
in the URL.
Patches
Patched with Version v2.3.3
Credits
Thanks to Kevin Pohl for reporting this.
Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint
High severity GitHub Reviewed Published Aug 12, 2024 in pxlrbt/filament-excel • Updated Aug 12, 2024