The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the PendingCommand class in PendingCommand.php.
References
| Link | Resource |
|---|---|
| https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/ | Third Party Advisory Exploit |
| https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html | Third Party Advisory |
Configurations
Information
Published : 2019-02-24 17:29
Updated : 2019-02-26 15:25
NVD link : CVE-2019-9081
Mitre link : CVE-2019-9081
JSON object : View
Products Affected
laravel
- framework
CWE
CWE-502
Deserialization of Untrusted Data
