Описание
An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
php-laravel-framework | not-affected | package |
Примечания
https://blog.laravel.com/security-release-laravel-61834-7232
EPSS
Процентиль: 59%
0.00379
Низкий
Связанные уязвимости
CVSS3: 7.5
nvd
почти 5 лет назад
An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.
CVSS3: 7.5
github
около 3 лет назад
Guard bypass in Eloquent models affecting Laravel illuminate database component
EPSS
Процентиль: 59%
0.00379
Низкий