CVE-2022-2870

MEDIUM

Laravel 5.1 - Deserialization

Title source: llm

Description

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

Scores

CVSS v3 4.1
EPSS 0.0038
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-502
Status published

Affected Products (1)

laravel/laravel < 5.1.46

Timeline

Published Aug 17, 2022
Tracked Since Feb 18, 2026