vendor:
Laravel Framework
by:
Hosein Vita
8.8
CVSS
HIGH
Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
79
CWE
Product Name: Laravel Framework
Affected Version From: 8.70.1
Affected Version To: 8.70.1
Patch Exists: YES
Related CWE: CVE-2021-12345
CPE: a:laravel:laravel_framework:8.70.1
Platforms Tested: Windows/Linux
2021
PHP Laravel 8.70.1 – Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
We can bypass laravel image file upload functionality to upload arbitary files on the web server which let us run arbitary javascript and bypass the csrf token.
Mitigation:
Upgrade to the latest version of Laravel Framework