CVE-2024-52301
CVSS 3.1 Score 0.0 of 10 (low)
Details
Summary
CVE-2024-52301 is a vulnerability affecting Laravel, a popular web application framework. When the register_argc_argv PHP directive is enabled, users can manipulate query strings to alter the environment Laravel utilizes during request handling. This issue, which has been resolved in versions 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0, now prevents Laravel from considering argv values during environment detection on non-CLI SAPIs. This change mitigates the risk of attackers exploiting this vulnerability to gain unintended access or manipulate application behavior.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.