CVE-2017-16894 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 86.9% (pctl 100)
Patch early
A public exploit exists.
Description
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 86.92% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-11-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| laravel | laravel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit) | 2019-07-16 |
References
- http://packetstormsecurity.com/files/153641/PHP-Laravel-Framework-Token-Unserialize-Remote-Command-Execution.html
- http://whiteboyz.xyz/laravel-env-file-vuln.html
- https://twitter.com/finnwea/status/967709791442341888
- http://packetstormsecurity.com/files/153641/PHP-Laravel-Framework-Token-Unserialize-Remote-Command-Execution.html
- http://whiteboyz.xyz/laravel-env-file-vuln.html
- https://twitter.com/finnwea/status/967709791442341888
→ the Explorer · watch your stack · NVD