laravel-crud-wizard-free has File Validation Bypass
Moderate severity
GitHub Reviewed
Published
Mar 11, 2025
in
macropay-solutions/laravel-crud-wizard-free
•
Updated Mar 12, 2025
Package
Affected versions
< 3.4.17
Patched versions
3.4.17
Description
Published to the GitHub Advisory Database
Mar 12, 2025
Reviewed
Mar 12, 2025
Last updated
Mar 12, 2025
Impact
Medium
Patches
Version 3.4.17 fixes illuminate/validation v 8.0.0 to 11.44.0
Workarounds
Register \MacropaySolutions\LaravelCrudWizard\Providers\ValidationServiceProvider instead of Illuminate\Validation\ValidationServiceProvider::class if you are using illuminate/validation < 11.44.1
References
GHSA-78fx-h6xr-vch4
References