CVE-2018-15133
Summary
| CVE | CVE-2018-15133 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-09 19:29:00 UTC |
| Updated | 2024-01-17 02:00:00 UTC |
| Description | In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack. |
Risk And Classification
EPSS: 0.768140000 probability, percentile 0.994970000 (date 2026-07-21)
CISA KEV: Listed on 2024-01-16; due 2024-02-06; ransomware use Unknown
Problem Types: CWE-502
CISA Known Exploited Vulnerability
| Vendor | Laravel |
|---|---|
| Product | Laravel Framework |
| Name | Laravel Deserialization of Untrusted Data Vulnerability |
| Required Action | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
| Notes | https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30; https://nvd.nist.gov/vuln/detail/CVE-2018-15133 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHP Laravel Framework Token Unserialize Remote Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Upgrade Guide - Laravel - The PHP Framework For Web Artisans | CONFIRM | laravel.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.