CVE-2021-43617

CRITICAL

Laravel Framework <8.70.2 - Code Injection

Title source: llm

Description

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

Exploits (4)

exploitdb WORKING POC
by Hosein Vita · textwebappsphp
https://www.exploit-db.com/exploits/50525
nomisec WORKING POC 1 stars
by Sybelle03 · poc
https://github.com/Sybelle03/CVE-2021-43617
nomisec WORKING POC
by aweiiy · poc
https://github.com/aweiiy/CVE-2021-43617
nomisec STUB
by kombat1 · poc
https://github.com/kombat1/CVE-2021-43617

Scores

CVSS v3 9.8
EPSS 0.5277
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
laravel/framework < 8.70.2
laravel/framework 0Packagist
Published Nov 14, 2021
Tracked Since Feb 18, 2026