RULE(RULE ID:323894)

Rule General Information
Release Date: 2024-11-25
Rule Name: PHP Laravel Framework 5.5.21 Information Leakage Vulnerability (CVE-2017-16894)
Severity:
CVE ID:
Rule Protection Details
Description: Laravel Framework is a PHP-based Web application development framework developed by software developer Taylor Otwell. Security Vulnerabilities exist in Laravel Framework 5.5.21 and earlier versions. A remote attacker could exploit the vulnerability to obtain sensitive information.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: http://packetstormsecurity.com/files/153641/PHP-Laravel-Framework-Token-Unserialize-Remote-Command-Execution.html
http://whiteboyz.xyz/laravel-env-file-vuln.html
https://twitter.com/finnwea/status/967709791442341888
Solutions
Please contact the software vendor to update the software patch.