Executive brief
Laravel Framework contains a deserialization of untrusted data vulnerability in the decrypt method of the Encrypter component. An attacker can achieve remote code execution by sending a specially crafted X-XSRF-TOKEN value, provided they have knowledge of the application's encryption key (APP_KEY).
Affected products
- Laravel Laravel Framework through 5.5.40, 5.6.x through 5.6.29
Timeline
- 2018-08-09: disclosed: NVD Published Date
- 2024-01-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-16: exploited: Reported as exploited in the wild in CISA KEV update