PatchSiren cyber security CVE debrief
CVE-2019-25673 UniSharp CVE debrief
CVE-2019-25673 is an arbitrary file upload vulnerability in UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0. This vulnerability allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. The vulnerability can lead to arbitrary code execution by accessing the uploaded file through the working directory path. Security teams and administrators should review the vulnerability details and assess their exposure.
- Vendor
- UniSharp
- Product
- Laravel File Manager
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-05
- Advisory updated
- 2026-07-24
Who should care
Security teams and administrators responsible for UniSharp Laravel File Manager installations should be aware of this vulnerability and take necessary actions to mitigate it. They should review the vulnerability details, assess their exposure, and implement necessary security measures.
Technical summary
The vulnerability exists in the upload endpoint of UniSharp Laravel File Manager, allowing attackers to upload PHP files with the type parameter set to Files. This can lead to arbitrary code execution by accessing the uploaded file through the working directory path. The vulnerability affects UniSharp Laravel File Manager versions 2.0.0-alpha7 and 2.0. Security teams should review the vulnerability details, assess their exposure, and implement necessary security measures to mitigate the vulnerability. Affected product deployments should be identified and assigned an owner for follow-up. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified.
Defensive priority
High
Recommended defensive actions
- Update UniSharp Laravel File Manager to a version that fixes the arbitrary file upload vulnerability
- Restrict access to the upload endpoint to only trusted users
- Implement additional security measures, such as file type validation and monitoring for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-05T21:16:45.113Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Deferred. The vulnerability affects UniSharp Laravel File Manager versions 2.0.0-alpha7 and 2.0. Evidence is limited to public CVE and NVD information.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-25673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-25673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-25673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-25673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/UniSharp/laravel-filemanager
-
Source reference
Unverified legacy reference
URL: https://github.com/UniSharp/laravel-filemanager/issues/356
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/46389
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/unisharp-laravel-file-manager-alpha7-arbitrary-file-upload
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.