Record summary

CVE-2021-43617 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 2 repository PoCs, and 2 lab environments.

Description

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2
Lab environments
2

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 8.70.2affected

Proofs of concept

3

Catalogued exploits

ExploitDBPHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)ExploitDB exploitby Hosein VitaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubkombat1/CVE-2021-43617Repository PoCby kombat1Stars: 0Not analyzed1 file

550 B

GitHub

PoC details
GitHubSybelle03/CVE-2021-43617Repository PoCby Sybelle03Stars: 1Not analyzed94 files

402.2 KiB

GitHub

PoC details

Docker lab environments

2
GitHub

xss-csrf-vul

Sybelle03/CVE-2021-43617Created
Analysis pendingCVE-2021-43617Dockerfile

1 Dockerfile

Structural lab evidence is available; analysis is pending.

Packet coverage: some source evidence omitted

GitHub

docker-compose.yml

dangducloc/CVE_2021_43617Created
Analysis pendingCVE-2021-43617Compose · builds

1 Compose manifest · 1 Dockerfile · 1 service

Structural lab evidence is available; analysis is pending.

Packet coverage: some source evidence omitted

References

6