Executive brief
Ignition before 2.5.2, as used in Laravel and other products, contains a file upload vulnerability due to insecure usage of file_get_contents() and file_put_contents(). Unauthenticated remote attackers can exploit this on sites using debug mode to execute arbitrary code.
Affected products
- Facade Ignition < 2.5.2
- Laravel Laravel < 8.4.2
Timeline
- 2021-01-20: disclosed: Initial NVD analysis date
- 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-18: advisory