{"id":"GHSA-3fvf-2gp4-89wq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3fvf-2gp4-89wq","summary":"Possibility for Denial of Service by overwriting PHP files with language exports","details":"### Impact\nLaravel Translation Manager didn't check the locale name, which allowed directory traversal when exporting files. The content would be a PHP file returning an array of translations, but this could lead to unexpected results, like denial of service. Access to the Laravel Translation Manager is required, because a new locale would have to be added and published.\n\n### Patches\nVersion 0.6.2 fixes this issue.\n\n### Workarounds\nOnly allow trusted admins to publish/edit translations.\n\n### References\nhttps://github.com/barryvdh/laravel-translation-manager/pull/417\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/barryvdh/laravel-translation-manager\n* Email me (see Github profile)\n\n### Credits\nFound and reported by [Natalia Trojanowska](https://www.linkedin.com/in/trojanowskanatalia/)","published":"2022-03-18T23:17:15Z","modified":"2024-12-05T05:24:22.227992Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"barryvdh/laravel-translation-manager","fixedVersion":"0.6.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/barryvdh/laravel-translation-manager/security/advisories/GHSA-3fvf-2gp4-89wq"},{"type":"PACKAGE","url":"https://github.com/barryvdh/laravel-translation-manager"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:24:22.227992Z"}}