CVE-2024-51992
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Summary
CVE-2024-51992: A method exposure issue (CWE-749) was discovered in Orchid, a popular Laravel package used for back-end application development. Affecting Orchid Platform versions 8 through 14.42.x, this vulnerability exposes the Orchid Platform's asynchronous modal functionality to arbitrary method calls within the `Screen` class. Potential consequences include database table brute force, user credential validation checks, and disclosure of the server's real IP address. Users are advised to upgrade to the latest version, 14.43.0, released on November 6, 2024, to mitigate this risk. Alternatively, implementing middleware to validate and approve only authorized methods and parameters can help mitigate the vulnerability until upgrading is possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Platform