Описание
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.13.0 (исключая)
cpe:2.3:a:laravel_log_viewer_project:laravel_log_viewer:*:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.16169
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-312
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Plaintext Storage of Sensitive Information in Laravel Log Viewer before v0.13.0
EPSS
Процентиль: 95%
0.16169
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-312