ZeroHour

CVE-2020-24940

CVSS 3.1
7.5 high
EPSS
1%p66
Published
()
Modified
Description

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database in some situations in which table names are stripped during a mass assignment.

Vendors
laravel
Products
laravel
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.