Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m3px-vjxr-fx4m: Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint

Impact

The export download route /filament-excel/{path} allowed downloading any file without login when the webserver allows ../ in the URL.

Patches

Patched with Version v2.3.3

Credits

Thanks to Kevin Pohl for reporting this.

ghsa
#web#git

Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint

High severity GitHub Reviewed Published Aug 12, 2024 in pxlrbt/filament-excel • Updated Aug 12, 2024

ghsa: Latest News

GHSA-486g-47cc-8wxf: aiocpa contains credential harvesting code