CVE-2021-3129: Laravel Ignition
EPSS99.9%No. 102 of 1739 in KEV
CVE year2021~2 yrs before listing
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | Laravel |
| Product | Ignition |
| Name | Laravel Ignition File Upload Vulnerability |
| Added to KEV | 2023-09-18 |
| US federal due date | 2023-10-09 |
| Ransomware use | Known |
| CWE | – |
CISA description
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Laravel Ignition vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18.