Laravel
cpe:2.3:a:laravel:laravel:*:*:*:*:*:*:*
- < 6.18.34
- < 7.23.2
A vulnerability exists in Laravel versions prior to 6.18.34 and in the 7.x branch prior to 7.23.2, allowing unvalidated data to be saved to the database under certain conditions. This issue arises during mass assignment when table names are automatically removed, creating a potential for unexpected values to be recorded without proper validation.
Exploitation of this vulnerability could result in the database being populated with unvalidated and potentially harmful data.
Users can upgrade to Laravel 6.18.34 or 7.23.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.