RaqibCTI
CVE

CVE-2018-15133

P2
Laravel Deserialization of Untrusted Data Vulnerability
Laravel · Laravel Framework
Date added (CISA)
2024-01-16
Remediation due
2024-02-06
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16

Description

Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2018-15133: Laravel Deserialization of Untrusted Data Vulnerability · RaqibCTI