Showing 1 vulnerability on this page for Ignition

Signals CISA KEV Ransomware Nuclei
laravel vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unauthenticated remote code execution in Ignition

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

CWE-94Jan 12, 20211 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs30SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX