Логотип exploitDog
bind:CVE-2025-48490
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48490

Количество 2

Количество 2

nvd логотип

CVE-2025-48490

9 месяцев назад

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions), malicious actors could exploit this behavior by crafting requests that bypass expected validation rules, potentially injecting unexpected or dangerous parameters into the application. This could lead to unauthorized data being accepted or processed by the API, depending on the context in which the validation was bypassed. This issue has been patched in version 2.13.0.

EPSS: Низкий
github логотип

GHSA-69rh-hccr-cxrj

9 месяцев назад

Laravel Rest Api has a Search Validation Bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-48490

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions), malicious actors could exploit this behavior by crafting requests that bypass expected validation rules, potentially injecting unexpected or dangerous parameters into the application. This could lead to unauthorized data being accepted or processed by the API, depending on the context in which the validation was bypassed. This issue has been patched in version 2.13.0.

0%
Низкий
9 месяцев назад
github логотип
GHSA-69rh-hccr-cxrj

Laravel Rest Api has a Search Validation Bypass

0%
Низкий
9 месяцев назад

Уязвимостей на страницу