vendor:
Laravel log viewer
by:
Haboob Team
7.5
CVSS
HIGH
Local File Download (LFD)
434
CWE
Product Name: Laravel log viewer
Affected Version From: v0.12.0
Affected Version To: v0.12.0
Patch Exists: YES
Related CWE: CVE-2018-8947
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
Laravel log viewer by rap2hpoutre local file download (LFD)
Unauthorized user can access Laravel log viewer by rap2hpoutre and use download function to download any file with laravel permission, by base64 encode the wanted file.
Mitigation:
Update to version v0.13.0