Source: infosecwriteups.com

RCE on a Laravel Private Program

Category: Laravel, PHP

The recent Laravel CVE enables remote attackers to exploit a RCE flaw in websites using Laravel. By the way this post is originally published here and I decided to put it in Medium site too.

We have built this system for bug bounty hunting: here were roughly 526k live assets to filter for Laravel.

The one which is convenient for me on Laravel is sending permitted HTTP methods to endpoints (need more information?).

Follow the writers, publications, and topics that matter to you, and you’ll see them on your homepage and in your inbox.Explore
Newsletter

Get the latest Laravel/PHP jobs, events and curated articles straight to your inbox, once a week

Glimpse streamlines Laravel development by seamlessly deploying GitHub pull requests to preview environments with the help of Laravel Forge. Glimpse streamlines Laravel development by seamlessly deploying GitHub pull requests to preview environments with the help of Laravel Forge.
Fathom Analytics | Fast, simple and privacy-focused website analytics. Fathom Analytics | Fast, simple and privacy-focused website analytics.
Shirts painstakingly handcrafted by under-caffeinated developers. Shirts painstakingly handcrafted by under-caffeinated developers.
Community Partners