CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Published:Jan 12, 2021
Last Modified:Nov 10, 2025
EPS:Jan 12, 2021
EPSS Score:0.94287
CVSS Score:9.8
CISA Notification
Description
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Required Action:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes:
No extra notes provided.
Due Date
Oct 9, 2023
1068 days ago
Alert Date
Sep 18, 2023
1089 days ago
Affected Products
Vendor
Product
Action
Vendor
Facade
Product
Ignition
Facade
Ignition
Vendor
Laravel
Product
Laravel
Laravel
Laravel
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
