CVE-2019-9185: Unrestricted Upload of File with Dangerous Type
(updated )
Controller/Async/FilesystemManager.php
in the filemanager in Bolt allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php
extension.
References
Detect and mitigate CVE-2019-9185 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →