Laravel Reflected XSS via Request Parameter in Debug-Mode Error Page
Vulnerability Description
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-13918
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Fabian Funder (SBA Research)
- Philipp Adelsberger (SBA Research)
- Jeremy Angele
References
Affected Vendor
Laravel Holdings Inc.
View all reports →