QID 730626
Date Published: 2022-10-27
QID 730626: Ignition Laravel Debug Remote Code Execution (RCE) Vulnerability
Laravel is a free and open-source PHP web framework. Laravel ignition versions prior to 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
QID Detection Logic:(Unauthenticated):
This QID sends a specially crafted HTTP request to '/_ignition/execute-solution' and identifies the vulnerable instance based on the HTTP response.
It allows unauthenticated remote attackers to execute arbitrary code.
Solution
Customers are advised to upgrade to latest version.
Vendor References
- Ignition Laravel Debug RCE Vulnerability -
www.ambionics.io/blog/laravel-debug-rce
CVEs related to QID 730626
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|