EXPOSURES › CVE-2021-3129
CVE-2021-3129
CRITICAL ⌖ ON CISA KEV · EXPLOITEDUnauthenticated attackers could execute arbitrary code via a file upload vulnerability in Laravel Ignition.
Laravel Ignition allowed unauthenticated remote attackers to execute malicious code through insecure file handling. DIB organizations must ensure all software components are patched and monitored for KEV-listed vulnerabilities to prevent ransomware and supply-chain compromises. This failure demonstrates the critical need for rigorous supply-chain validation and continuous vulnerability management.
Shame score — A known, actively exploited vulnerability in a widely used PHP framework component that enabled unauthenticated remote code execution, directly linking to ransomware campaigns.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().