Impact
This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.
Applications are impacted when they:
- validate uploads using
is_image or mime_in without an independent safe extension check, such as ext_in on patched versions
- save uploaded files using the client-supplied filename
- place uploads in a web-accessible directory where PHP files can execute
Patches
Upgrade to v4.7.4 or later.
Workarounds
- Save uploads outside the public web root, preferably under
writable/uploads.
- Use
$file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.
- Disable script execution in any public upload directory.
- Manually verify the client filename extension before moving the file.
- For image uploads, reject files when
$file->getClientExtension() is not an allowed image extension.
- For exact MIME-type validation, reject files when
$file->getClientExtension() does not match $file->guessExtension().
References
Impact
This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.
Applications are impacted when they:
is_imageormime_inwithout an independent safe extension check, such asext_inon patched versionsPatches
Upgrade to v4.7.4 or later.
Workarounds
writable/uploads.$file->store()or$file->move($path, $file->getRandomName())instead of preserving the original client filename.$file->getClientExtension()is not an allowed image extension.$file->getClientExtension()does not match$file->guessExtension().References
ext_in