Impact
Backpack CRUD, part of Laravel's Backpack, builds admin panels with CRUD operations. In vulnerable releases older than version 6.8.12 (and 7.0.35) and the final 5.x releases, the HasUploadFields::uploadMultipleFilesToDisk method accepts disk‑relative paths supplied via the clear_<attribute>[] mutator and forwards them to Storage::disk()->delete without confirming that the paths belong to the current model. An attacker who can authenticate and has Update access to a CRUD that uses this mutator can submit any file path on the configured disk; the system will delete that file, allowing removal of another record’s attachment, a shared asset, or other operational files. The newer MultipleFiles uploader mitigates this by intersecting the requested deletions with the persisted file list, and the flaw does not permit reading deleted files.
Affected Systems
Laravel Backpack CRUD versions prior to 6.8.12 and 7.0.35 are susceptible to this issue, as is the 5.x branch through its final releases. Any deployment that installs these vulnerable releases on a Laravel environment with an update‑permitted CRUD interface faces the risk. The affected artifact is the src/app/Models/Traits/HasUploadFields.php trait, which is commonly used in Backpack CRUD projects to manage file uploads. The same vulnerability affects any user‑credential that can exercise Update permissions on a CRUD that uses the HasUploadFields mutator.
Risk and Exploitability
The CVSS score of 8.1 classifies this vulnerability as high severity, reflecting that an authenticated attacker with Update privileges can remove arbitrary files. The EPSS score indicates an exploitation probability of less than 1 %, suggesting a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need only a valid user session with Update rights, which is common in many administration interfaces. While deletion does not provide code execution, it compromises data integrity and availability. The issue remains exploitable until the vulnerable package is updated or mitigated.
OpenCVE Enrichment
Github GHSA