CVSS v3
8.1
HIGH
EPSS Score
86.0 %
exploit probability
CISA KEV
Yes
known exploited
Exploitation
—
SSVC status
Description
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
CISA Known Exploited Vulnerability
- Date Added
- 2024-01-16
- Patch Due Date
- 2024-02-06
- Ransomware Use
- Unknown
Technical details
- Published
- 2018-08-09
- Exploit-DB
- EDB-47129
Frequently asked questions
What is CVE-2018-15133?
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
Is CVE-2018-15133 actively exploited?
Yes. CVE-2018-15133 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2024-02-06.
What is the CVSS score for CVE-2018-15133?
CVE-2018-15133 has a CVSS v3 base score of 8.1 (HIGH severity).
Is CVE-2018-15133 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2018 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).