An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
| Software | From | Fixed in |
|---|---|---|
simogeo / filemanager
|
- | - |
simogeo / filemanager
|
0.8 | 1.1.x |
simogeo / filemanager
|
1.5.0 | 2.0.0.x |