CRITICAL KEV Used in ransomware campaigns
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents()
Published Jan 12, 2021 ·Due Oct 9, 2023
9.8
CRITICALCVSS 3.1
EPSS 99.94%
Description
Affected products
Remediation
References (9)
Change history (0)
No recorded changes yet.