← All CVEs

CVE-2018-8947

high · 7.5

rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.

7.5
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2018-03-25
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-312

Affected products

VendorProductAffected versions
laravel_log_viewer_projectlaravel_log_viewer< 0.13.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8947