RaqibCTI
CVE

CVE-2021-3129

P1⬤ KNOWN RANSOMWARE USE
Laravel Ignition File Upload Vulnerability
Laravel · Ignition
Date added (CISA)
2023-09-18
Remediation due
2023-10-09
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16

Description

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

Source: NVD ↗ · CISA KEV Catalog ↗