CVE-2020-24940 – illuminate/database
Package
Manager: composer
Name: illuminate/database
Vulnerable Version: >=5.5.0 <=5.5.44 || >=6.0.0 <6.18.34 || >=7.0.0 <7.23.2
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00261 pctl0.4925
Details
Guard bypass in Eloquent models affecting Laravel illuminate database component An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database component in some situations in which table names are stripped during a mass assignment.
Metadata
Created: 2022-05-24T17:27:24Z
Modified: 2024-05-15T20:22:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c7rm-w2hj-x8g3/GHSA-c7rm-w2hj-x8g3.json
CWE IDs: []
Alternative ID: GHSA-c7rm-w2hj-x8g3
Finding: F274
Auto approve: 1