logo
Home/CVEs/CVE-2021-3129/

CVE-2021-3129 - Laravel Ignition File Upload Vulnerability

Project:Laravel

Product:Ignition

Date Added:2023-09-18Due Date:2023-10-09

Vulnerability Name

Laravel Ignition File Upload Vulnerability

Description

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://github.com/facade/ignition/releases/tag/2.5.2

https://nvd.nist.gov/vuln/detail/CVE-2021-3129

Related News Articles

Cisco Previews AI Defenses to Cloud Security PlatformJanuary 21, 2025

CRYSTALRAY hacker expands to 1,500 breached systems using SSH-Snake toolJuly 11, 2024