CVE-2018-15133

Laravel Deserialization of Untrusted Data Vulnerability

8.1
CVSS 3.1
76.8 %
EPSS (current)
2024-01-16
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Laravel / Laravel Framework

Published: 2018-08-09 · Due (CISA): 2024-02-06

CWE: CWE-502 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
metasploitexploit/unix/http/laravel_token_unserialize_execexploit/unix/http/laravel_token_unserialize_exec2018-08-07
exploitdb47129PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)2019-07-16

References only — no downloads or instructions.

Sources