CVE-2018-8947
Last modified
CVE-2018-8947 is a vulnerability of currently unknown severity. rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.. EPSS estimates a 11.63% chance of exploitation in the next 30 days.
Description
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Laravel Log Viewer Project | Laravel Log Viewer | < 0.13.0 |
References
- https://github.com/rap2hpoutre/laravel-log-viewer/commit/cda89c06dc5331d06fab863d7cb1c4047ad68357Patch, Third Party Advisory
- https://github.com/rap2hpoutre/laravel-log-viewer/releases/tag/v0.13.0Third Party Advisory
- https://www.exploit-db.com/exploits/44343/Exploit, Third Party Advisory, VDB Entry
- https://github.com/rap2hpoutre/laravel-log-viewer/commit/cda89c06dc5331d06fab863d7cb1c4047ad68357Patch, Third Party Advisory
- https://github.com/rap2hpoutre/laravel-log-viewer/releases/tag/v0.13.0Third Party Advisory
- https://www.exploit-db.com/exploits/44343/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-8947?
How severe is CVE-2018-8947?
How do I fix CVE-2018-8947?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-8940ClientServiceConfigController.cs in Enghouse Cloud Contact C…
- CVE-2018-8941Diagnostics functionality on D-Link DSL-3782 devices with fi…
- CVE-2018-8942Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.
- CVE-2018-8943There is a SQL injection in the PHPSHE 1.6 userbank paramete…
- CVE-2018-8944PHPOK 4.8.338 has an arbitrary file upload vulnerability.
- CVE-2018-8945The bfd_section_from_shdr function in elf.c in the Binary Fi…
- CVE-2018-8948In MISP before 2.4.89, app/View/Events/resolved_attributes.c…
- CVE-2018-8949An issue was discovered in app/Model/Attribute.php in MISP b…
- CVE-2018-8953CA Workload Automation AE before r11.3.6 SP7 allows remote a…
- CVE-2018-8954CA Workload Control Center before r11.4 SP6 allows remote at…
- CVE-2018-8955The installer for BitDefender GravityZone relies on an encod…
- CVE-2018-8956ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow …5.3
Are you affected by CVE-2018-8947?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
