{"id":"CVE-2022-0472","aliases":["GHSA-5q5w-mqp6-g2gh"],"url":"https://o3.security/vulnerability/CVE-2022-0472","summary":"Unrestricted Upload of File with Dangerous Type in jsdecena/laracom","details":"Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.","published":"2022-02-04T22:32:06Z","modified":"2026-08-12T03:51:12.200966555Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"jsdecena/laracom","fixedVersion":"2.0.9"}],"fix":{"url":"https://github.com/jsdecena/laracom/commit/256026193ce994dc4c1365e02f414d8a0cd77ae8","label":"jsdecena/laracom@2560261"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/cb5b8563-15cf-408c-9f79-4871ea0a8713"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0472.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0472"},{"type":"FIX","url":"https://github.com/jsdecena/laracom/commit/256026193ce994dc4c1365e02f414d8a0cd77ae8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.200966555Z"}}