Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2019-17494

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
Attacker Value
Unknown

CVE-2019-17433

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
Attacker Value
Unknown

CVE-2018-20962

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
0
Attacker Value
Unknown

CVE-2018-6330

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.
0
Attacker Value
Unknown

CVE-2018-18888

Disclosure Date: November 01, 2018 (last updated November 27, 2024)
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
0
Attacker Value
Unknown

CVE-2018-15133

Disclosure Date: August 09, 2018 (last updated June 11, 2024)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
Attacker Value
Unknown

CVE-2018-8947

Disclosure Date: March 25, 2018 (last updated November 26, 2024)
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
0
Attacker Value
Unknown

CVE-2017-16894

Disclosure Date: November 20, 2017 (last updated February 15, 2024)
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.
0
Attacker Value
Unknown

CVE-2017-14775

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
0
Attacker Value
Unknown

CVE-2017-9303

Disclosure Date: May 29, 2017 (last updated November 26, 2024)
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.
0