Laravel-Mediable 7.0.0 至 7.0.2 版本之前的版本中,针对 CVE-2026-49972 的安全补丁不完整。具体而言, 配置文件中的 (禁止扩展名)黑名单缺少 扩展名。为解决 CVE-2026-49972 而引入的黑名单仅包含了 ,却遗漏了 。在 Debian 和 Ubuntu 系统上,Apache 默认通过 指令将 文件作为 PHP 代码执行。 由于 不在黑名单中,攻击者可以上传一个 文件,该文件能够通过 和 中的所有验证逻辑。文件随后被写入磁盘,并在被请求时作为 PHP 代码执行,从而
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| plank | laravel-mediable | 7.0.0< 7.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| plank | laravel-mediable | 7.0.0 ~ 7.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet