CVE-2019-25673Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-05: 2Mentions · 2026-04-07: 1Technical Details · 2026-04-05: 2Technical Details · 2026-04-07: 104-0504-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-052
Disclosure2
2026-04-071
Disclosure1
Full discourse3 posts
  • Firmis Labs@FirmisLabs
    Disclosure

    CVE-2019-25673 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2019-25673

    Post summary

    The post shares the CVE‑2019‑25673 identifier and its NIST severity rating with a link to the official NVD entry.

    1000021
    1 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25673: HIGH] Beware! UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 versions are vulnerable to arbitrary file uploads, enabling attackers to execute malicious code through PHP files.#cve,CVE-2019-25673,#cybersecurity https://cvefind.com/CVE-2019-25673

    Post summary

    The tweet announces that UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 are vulnerable to arbitrary file uploads that allow malicious PHP code execution, rated HIGH severity, with no patch or active exploitation reported.

    0000058
    612 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25673 UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by s… https://www.cve.org/CVERecord?id=CVE-2019-25673

    Post summary

    CVE-2019-25673 is identified as an authenticated arbitrary file upload vulnerability in UniSharp Laravel File Manager, with no PoC, patch, or active exploitation details provided.

    00000191
    56.8K followersView on X

Explore more