backpack/crud 为 Backpack 提供增删改查(CRUD)功能,Backpack 是一套用于帮助用户构建自定义管理面板的 Laravel 包集合。从 6.0.0 到 6.8.14 以及 7.0.38 版本中,通过 CrudTrait 调用的 HasUploadFields 方法 和 ,以及通过 的 路径,均未在内部拒绝可被服务器执行的类型。 当公共磁盘(public disk)可通过 实现 Web 访问,且 Web 服务器与 PHP-FPM 配置能够执行所存储文件的扩展名时,拥有上传功能的 CRUD
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Laravel-Backpack | CRUD | >= 6.0.0, < 6.8.14 |
affected |
>= 7.0.0, < 7.0.38 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Laravel-Backpack | CRUD | >= 6.0.0, < 6.8.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54178 | 8.1 HIGH | backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUpload |
| CVE-2026-54182 | 8.1 HIGH | backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host |
| CVE-2026-54175 | 7.6 HIGH | backpack/crud: Unverified password change in MyAccountController via mass assignment |
| CVE-2026-54180 | 7.6 HIGH | backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cr |
| CVE-2026-54176 | 6.5 MEDIUM | backpack/crud: MyAccountController allows changing the login email without a current-passw |
| CVE-2026-57570 | 6.5 MEDIUM | backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (I |
| CVE-2026-54181 | 5.4 MEDIUM | backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are |
No comments yet