Exploited Vulnerabilities Daily
🌐 English

Home › Laravel

CVE-2021-3129: Laravel Ignition

EPSS99.9%No. 102 of 1739 in KEV
CVE year2021~2 yrs before listing
Same vendor in KEV3
Same product1
FieldValue
VendorLaravel
ProductIgnition
NameLaravel Ignition File Upload Vulnerability
Added to KEV2023-09-18
US federal due date2023-10-09
Ransomware useKnown
CWE–

CISA description

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

NVD — CVE-2021-3129

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Laravel Ignition vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18.