CVE-2021-43808Cross-site Scripting in Framework

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8

Description

Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user taken to another location in their browser due to XSS. This is due to the user being able to guess the parent placeholder SHA-1 hash by trying common names of sections. If the parent template contains an exploitable HTML structure an XSS vulnerability can be expos

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDlaravel/framework7.0.07.30.6+2
Packagistlaravel/framework7.0.07.30.6+2
debiandebian/php-laravel-framework< php-laravel-framework 6.20.14+dfsg-3 (bookworm)
CVEListV5laravel/framework>= 7.0.0, < 7.30.6, >= 8.0.0, < 8.75.0+1
Packagistilluminate/view7.0.07.30.6+2

Patches

🔴Vulnerability Details

3
OSV
Laravel Framework XSS in Blade templating engine2021-12-08
GHSA
Laravel Framework XSS in Blade templating engine2021-12-08
OSV
CVE-2021-43808: Laravel is a web application framework2021-12-08

📋Vendor Advisories

1
Debian
CVE-2021-43808: php-laravel-framework - Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6...2021
CVE-2021-43808 — Cross-site Scripting in Framework | cvebase