CVE-2018-8947
Plaintext Storage of Sensitive Information in Laravel Log Viewer before v0.13.0
7.5
HIGH
CVSS 3.1
EPSS 11.6%
Description
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
How to fix CVE-2018-8947
To remediate CVE-2018-8947, upgrade the affected package to a fixed version below.
- —upgrade to 0.13.0 or later
Is CVE-2018-8947 being exploited?
Moderate — EPSS is 11.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.13.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |