peter bassill · operator
$ cve CVE-2018-8947 JSON

CVE-2018-8947 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 11% (pctl 96)

Patch early

A public exploit exists.

Description

rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS11.02% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-312
On CISA KEVno
Public exploityes
Published2018-03-25
Last modified2026-06-17

Affected (1)

VendorProduct
laravel log viewer projectlaravel log viewer

Public exploits

SourceTitleDate
exploit-dbLaravel Log Viewer < 0.13.0 - Local File Download2018-03-26

References

→ the Explorer  ·  watch your stack  ·  NVD