CVE detail
CVE-2020-10963 — CVE-2020-10963
Published 2020-03-25 · Modified 2026-06-17 · Vendor frozennode · Product laravel-administrator · Source nvd
HIGH
severity
CVSS-derived band
0.1467
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References