laravel Vulnerabilities and Affected Products
Vulnerabilities associated with Ignition.
Products
Clear product- framework5 vulnerabilities
- Laravel Framework4 vulnerabilities
- livewire3 vulnerabilities
- reverb2 vulnerabilities
- Ignition1 vulnerability
- Laravel Valet1 vulnerability
- passport1 vulnerability
- pulse1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-3129CRITICAL | Unauthenticated remote code execution in IgnitionIgnition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2. | CVSS9.8v3.1 | EPSS>99.9% | PoCs30 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |