The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:NLaravel Framework
APPLaravel11.9.0 – 11.36.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-43617CRITICAL9.8PL ✓same product
Laravel Framework — brak blokady przesyłania plików .phar (RCE)
CVE-2024-13919HIGH8.0same product
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting du...
CVE-2024-52301HIGH8.7same product
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users cal...
CVE-2020-19316HIGH8.8same product
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
CVE-2018-6330HIGH8.8same product
Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.