PT-2024-40241 · Laravel · Laravel

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: Laravel versions prior to 4.1.29
Description: The issue concerns mass assignment vulnerabilities in Laravel when not using the fillable property on models or when using guarded and passing user-controlled arrays into update or save functions. This could put applications at risk if they are using versions prior to the fix.
Recommendations: For versions prior to 4.1.29, upgrade to 4.1.29 immediately to protect against mass assignment vulnerabilities. As a temporary workaround, consider restricting the use of guarded properties when passing user-controlled arrays into update or save functions until the upgrade is applied.

RCE

Weakness Enumeration

Related Identifiers

GHSA-CC2W-GHC5-M5QR

Affected Products

Laravel