Junglewise Threat Intelligence

CVE-2018-15133: Laravel Framework RCE Vulnerability

CVE-2018-15133 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-14

Vendors: Laravel.

Executive brief

Laravel Framework contains a deserialization of untrusted data vulnerability in the decrypt method of the Encrypter component. An attacker can achieve remote code execution by sending a specially crafted X-XSRF-TOKEN value, provided they have knowledge of the application's encryption key (APP_KEY).

Affected products

  • Laravel Laravel Framework through 5.5.40, 5.6.x through 5.6.29

Timeline

  • 2018-08-09: disclosed: NVD Published Date
  • 2024-01-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-16: exploited: Reported as exploited in the wild in CISA KEV update