CyberSec.Space Logo
Back to CVE Browser

CVE-2021-43996

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0360%
EPSS Percentile12.11th
PublishedNov 17, 2021
Last ModifiedNov 21, 2024

Vulnerability Description

The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

Affected Platforms (CPE)

πŸ“¦
Facade

Ignition

< 1.6.15
πŸ“¦
Facade

Ignition

>= 2.0.0 and < 2.0.6

References & Advisories

Related Vulnerabilities