CVE-2020-24941Incorrect Authorization in Laravel

Severity
7.5HIGHNVD
EPSS
0.2%
top 56.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateMay 6

Description

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDlaravel/laravel7.0.07.24.0+1
Packagistlaravel/framework7.0.07.24.0+1

🔴Vulnerability Details

2
GHSA
Improper Input Validation in Laravel2021-05-06
OSV
Improper Input Validation in Laravel2021-05-06

📋Vendor Advisories

1
Debian
CVE-2020-24941: php-laravel-framework - An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $gu...2020
CVE-2020-24941 — Incorrect Authorization in Laravel | cvebase