CVE-2018-15133
Laravel Deserialization of Untrusted Data Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 8.1
- EPSS
- 76.8% 백분위 99.5% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2024.02.06
- 공개일
- 2018.08.10
CISA KEV에 등록된 실제 악용 확인 취약점
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
공급사 Laravel
제품 Laravel Framework
영향 버전 n/a, <= 5.5.40, >= 5.6.0 <= 5.6.29
수정 버전 공식 출처에서 확인 필요
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2024.02.06CVSS 벡터 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-502
KEV 등록일 2024.01.16
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30; https://nvd.nist.gov/vuln/detail/CVE-2018-15133
EPSS 데이터 기준일 2026.06.27