CVE-2018-8947
high · 7.5rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
7.5
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2018-03-25
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-312
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| laravel_log_viewer_project | laravel_log_viewer | < 0.13.0 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/rap2hpoutre/laravel-log-viewer/commit/cda89c06dc5331d06fab863d7cb1c4047ad68357
- https://github.com/rap2hpoutre/laravel-log-viewer/releases/tag/v0.13.0
- https://www.exploit-db.com/exploits/44343/
- https://github.com/rap2hpoutre/laravel-log-viewer/commit/cda89c06dc5331d06fab863d7cb1c4047ad68357
- https://github.com/rap2hpoutre/laravel-log-viewer/releases/tag/v0.13.0
- https://www.exploit-db.com/exploits/44343/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-8947