Impact
In Laravel-Backpack:CRUD versions 6.0.0 through 6.8.14 and 7.0.38, the HasUploadFields upload helpers do not reject executable file types. An authenticated administrator can upload a file such as shell.php using an upload-enabled CRUD field that lacks MIME or type validation. When the public disk is exposed through php artisan storage:link, the file is stored with its attacker-supplied extension; the web server and PHP-FPM then interpret and execute the file, granting remote code execution. The legacy path preserves the extension, and the newer path derives an extension without blocking dangerous types. The issue is fixed in 6.8.14 and 7.0.38.
Affected Systems
The affected package is Laravel‑Backpack:CRUD. Vulnerable releases are 6.0.0 up to and including 6.8.14 and 7.0.38. All later releases contain the fix that rejects or blocks dangerous extensions. Any environment using one of those versions on a Laravel project is at risk.
Risk and Exploitability
The CVSS score of 6.6 indicates medium severity. The EPSS score of < 1% indicates a low exploitation probability, and the vulnerability is not listed in CISA KEV. An attacker must first authenticate as an administrator with CRUD access, then upload a file to a public disk linked via php artisan storage:link. After the file is stored with its original extension on the web‑accessible disk, the web server’s PHP interpreter executes it, yielding full remote code execution. The exploit requires no special network access beyond normal administrative operations and therefore is likely to be targeted once discovered.
OpenCVE Enrichment
Github GHSA