CVE-2021-3129

unknown KEV
Published 2021-03-29 · Modified 2023-09-18
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
1.5

Description

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

CISA KEV

Vendor
Laravel
Product
Ignition
Due date
2023-10-09

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://github.com/facade/ignition/releases/tag/2.5.2; https://nvd.nist.gov/vuln/detail/CVE-2021-3129

Exploits

Package impact

EcosystemPackageVulnerableFixed
php Packagistfacade/ignition>=2.5.0,<2.5.22.5.2
php Packagistfacade/ignition>=2.0.0,<2.4.22.4.2
php Packagistfacade/ignition>=1.7.0,<1.16.141.16.14
php Packagistfacade/ignition<1.6.151.6.15

References

Verify integrity in audit chain (admin only). AS-IS.