CVE-2024-21546 affects unisharp/laravel-filemanager versions prior to 2.9.1. The vulnerability allows remote code execution through an upload validation bypass: an attacker can supply a file with a valid MIME type while inserting an additional '.' after the .php extension, enabling a PHP payload to be accepted and later executed by the server. Based on the available information, the issue is in the package's file upload handling and extension validation logic, which insufficiently restricts dangerous file types.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an operational standalone Python exploit for CVE-2024-21546, a Nuclei panel-discovery template, and documentation. The primary entry point, cve_2024_21546_rce.py, accepts a host, optional port and scheme, command, interactive mode, and Laravel Filemanager working directory. It probes HTTPS then HTTP unless explicitly configured, maintains an HTTP session with TLS verification disabled, verifies unauthenticated panel access, extracts a CSRF token, and enumerates the jsonitems endpoint before and after uploading a file. The intended exploit chain uploads a PHP payload whose filename ends in a dot, bypassing the vulnerable extension blocklist because the apparent extension becomes empty; it then finds the uploaded server-generated name and uses the Filemanager rename capability to give it a .php extension. The resulting PHP webshell accepts Base64 command input through X-Cmd and executes it via dynamically constructed passthru, with interactive and single-command modes and an intended cleanup step. laravel-filemanager.yaml is a separate Nuclei detection-only template that identifies an accessible panel using a 200 response and vendor/upload asset markers, avoiding reliance on localized English UI text. It detects exposure, not CVE exploitation.
This repository contains a Python exploit script (CVE-2024-21546.py) and a README.md. The exploit targets UniSharp Laravel Filemanager (version 2.9.1 and prior) and leverages CVE-2024-21546, which allows authenticated users to bypass file upload restrictions and achieve remote code execution (RCE). The script requires a valid 'laravel_session' cookie for authentication. It validates the session, extracts a CSRF token, uploads a PHP reverse shell disguised as a PNG file (using a filename bypass technique), and then triggers the shell to connect back to the attacker's listener. The README provides usage instructions, affected versions, and references. The main attack vector is network-based, exploiting web endpoints for file upload and execution. The exploit is operational, providing a working reverse shell payload, but requires manual setup of a listener and a valid session.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.