← Back to browse · API

CVE-2018-15133

Severity
HIGH
CVSS
8.1
EPSS
0.76814
Risk score
84.28
CISA KEV
Yes
PoC
No
Published
2024-01-16
Modified
2024-01-16
First seen
2026-08-07
Aliases
EUVD-2022-5039, GHSA-QVQM-H22R-4CP9
Products
Laravel:Laravel Framework, n/a:n/a n/a
Sources
euvd EUVD-2022-5039
cisa.gov CVE-2018-15133

Description

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

References