CVE-2021-3129

CRITICAL KEV RANSOMWARE NUCLEI

Ignition <2.5.2 - RCE

Title source: llm

Description

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

Exploits (34)

nomisec WORKING POC 285 stars
by ambionics · poc
https://github.com/ambionics/laravel-exploits
nomisec WORKING POC 161 stars
by zhzyker · remote
https://github.com/zhzyker/CVE-2021-3129
nomisec WORKING POC 131 stars
by SNCKER · remote
https://github.com/SNCKER/CVE-2021-3129
nomisec WORKING POC 131 stars
by joshuavanderpoll · remote
https://github.com/joshuavanderpoll/CVE-2021-3129
nomisec WORKING POC 77 stars
by SecPros-Team · remote
https://github.com/SecPros-Team/laravel-CVE-2021-3129-EXP
nomisec WORKING POC 68 stars
by nth347 · remote
https://github.com/nth347/CVE-2021-3129_exploit
nomisec WORKING POC 18 stars
by crisprss · remote
https://github.com/crisprss/Laravel_CVE-2021-3129_EXP
nomisec WORKING POC 13 stars
by ajisai-babu · remote
https://github.com/ajisai-babu/CVE-2021-3129-exp
nomisec WORKING POC 12 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2021-3129
nomisec WORKING POC 9 stars
by 0x0d3ad · remote
https://github.com/0x0d3ad/CVE-2021-3129
nomisec WORKING POC 8 stars
by cuongtop4598 · remote
https://github.com/cuongtop4598/CVE-2021-3129-Script
nomisec SCANNER 7 stars
by MadExploits · poc
https://github.com/MadExploits/Laravel-debug-Checker
nomisec WORKING POC 6 stars
by shadowabi · remote
https://github.com/shadowabi/Laravel-CVE-2021-3129
nomisec WORKING POC 6 stars
by 0nion1 · remote
https://github.com/0nion1/CVE-2021-3129
nomisec WORKING POC 5 stars
by Axianke · remote
https://github.com/Axianke/CVE-2021-3129
nomisec WORKING POC 2 stars
by wmasday · remote
https://github.com/wmasday/CVE-2021-3129
nomisec WORKING POC 2 stars
by FunPhishing · remote
https://github.com/FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
nomisec WORKING POC 1 stars
by idea-oss · poc
https://github.com/idea-oss/laravel-CVE-2021-3129-EXP
nomisec WORKING POC 1 stars
by keyuan15 · remote
https://github.com/keyuan15/CVE-2021-3129
nomisec WORKING POC 1 stars
by JacobEbben · remote
https://github.com/JacobEbben/CVE-2021-3129
nomisec WORKING POC
by piperpwn · remote
https://github.com/piperpwn/CVE-2021-3129-piperpwn
nomisec WORKING POC
by Prabesh01 · poc
https://github.com/Prabesh01/hoh4
nomisec SCANNER
by banyaksepuh · poc
https://github.com/banyaksepuh/Mass-CVE-2021-3129-Scanner
nomisec WORKING POC
by miko550 · remote
https://github.com/miko550/CVE-2021-3129
nomisec WORKING POC
by cc3305 · remote
https://github.com/cc3305/CVE-2021-3129
nomisec WORKING POC
by Y0s9 · poc
https://github.com/Y0s9/CVE-2021-3129
nomisec WORKING POC
by Zoo1sondv · remote
https://github.com/Zoo1sondv/CVE-2021-3129
nomisec WORKING POC
by lukwagoasuman · remote
https://github.com/lukwagoasuman/CVE-2021-3129---Laravel-RCE
nomisec SCANNER
by GodOfServer · infoleak
https://github.com/GodOfServer/CVE-2021-3129
nomisec WORKING POC
by hupe1980 · remote
https://github.com/hupe1980/CVE-2021-3129
exploitdb WORKING POC
by SunCSR Team · pythonwebappsphp
https://www.exploit-db.com/exploits/49424
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/php/ignition_laravel_debug_rce.rb

Nuclei Templates (1)

Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution
CRITICALby z3bd,pdteam

Scores

CVSS v3 9.8
EPSS 0.9429
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2023-09-18
VulnCheck KEV 2021-03-18
InTheWild.io 2021-04-08
ENISA EUVD EUVD-2021-0599
Ransomware Use Confirmed

Classification

Status published

Affected Products (2)

facade/ignition < 2.5.2
facade/ignition < 2.5.2Packagist

Timeline

Published Jan 12, 2021
KEV Added Sep 18, 2023
Tracked Since Feb 18, 2026