← Back

CVE-2020-24940

nvd nist
Published: Sep 4, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.

Affected (2)

Products: Laravel: Laravel
1 product
Laravel
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Laravel
Before 6.18.34
From 7.0.0 to 7.23.2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.