Source: infosecwriteups.com

RCE on a Laravel Private Program

Category: Laravel, PHP

The recent Laravel CVE enables remote attackers to exploit a RCE flaw in websites using Laravel. By the way this post is originally published here and I decided to put it in Medium site too.

We have built this system for bug bounty hunting: here were roughly 526k live assets to filter for Laravel.

The one which is convenient for me on Laravel is sending permitted HTTP methods to endpoints (need more information?).

Follow the writers, publications, and topics that matter to you, and you’ll see them on your homepage and in your inbox.Explore
Newsletter

Get the latest Laravel/PHP jobs, events and curated articles straight to your inbox, once a week

Fathom Analytics | Fast, simple and privacy-focused website analytics. Fathom Analytics | Fast, simple and privacy-focused website analytics.
Achieve superior email deliverability with ToastMail! Our AI-driven tool warms up inboxes, monitors reputation, and ensures emails reach their intended destination. Sign up today for a spam-free future. Achieve superior email deliverability with ToastMail! Our AI-driven tool warms up inboxes, monitors reputation, and ensures emails reach their intended destination. Sign up today for a spam-free future.
Community Partners