laravel framework CVE-2021-43617 is a vulnerability in Laravel Framework
Published on November 14, 2021

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

NVD


Products Associated with CVE-2021-43617

Want to know whenever a new CVE is published for Laravel Framework? stack.watch will email you.

 

Exploit Probability

EPSS
52.77%
Percentile
97.89%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.