Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Laravel

Laravelвеб-фреймворк с открытым кодом, предназначенный для разработки с использованием архитектурной модели MVC

Релизный цикл, информация об уязвимостях

Продукт: Laravel
Вендор: laravel

График релизов

121320252026202720282029

Недавние уязвимости Laravel

Количество 40

nvd логотип

CVE-2020-24940

почти 6 лет назад

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-24940

почти 6 лет назад

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23. ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-15133

почти 8 лет назад

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

CVSS3: 8.1
EPSS: Высокий
debian логотип

CVE-2018-15133

почти 8 лет назад

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote c ...

CVSS3: 8.1
EPSS: Высокий
nvd логотип

CVE-2017-16894

больше 8 лет назад

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2017-16894

больше 8 лет назад

In Laravel framework through 5.5.21, remote attackers can obtain sensi ...

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2017-14775

почти 9 лет назад

Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2017-14775

почти 9 лет назад

Laravel before 5.5.10 mishandles the remember_me token verification pr ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2017-9303

около 9 лет назад

Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-9303

около 9 лет назад

Laravel 5.4.x before 5.4.22 does not properly constrain the host porti ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-24940

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-24940

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23. ...

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2018-15133

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

CVSS3: 8.1
77%
Высокий
почти 8 лет назад
debian логотип
CVE-2018-15133

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote c ...

CVSS3: 8.1
77%
Высокий
почти 8 лет назад
nvd логотип
CVE-2017-16894

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

CVSS3: 7.5
87%
Высокий
больше 8 лет назад
debian логотип
CVE-2017-16894

In Laravel framework through 5.5.21, remote attackers can obtain sensi ...

CVSS3: 7.5
87%
Высокий
больше 8 лет назад
nvd логотип
CVE-2017-14775

Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

CVSS3: 5.9
1%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-14775

Laravel before 5.5.10 mishandles the remember_me token verification pr ...

CVSS3: 5.9
1%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-9303

Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
debian логотип
CVE-2017-9303

Laravel 5.4.x before 5.4.22 does not properly constrain the host porti ...

CVSS3: 6.1
1%
Низкий
около 9 лет назад

Уязвимостей на страницу


Поделиться