Code Injection in Ignition - CVE-2021-3129
Published: January 12, 2021 / Updated: October 9, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation in Ignition. A remote attacker can send a specially crafted request to the application and read or write arbitrary files on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
laravel
How to mitigate CVE-2021-3129
laravel - update to 8.4.3
Links to Public Exploits and PoC-codes
- Exploit #10568 - CVE-2021-3129 (CVE-2021-3129 (Laravel Ignition RCE Exploit)) (October 9, 2024)
- Exploit #9591 - CVE-2021-3129 (CVE-2021-3129) (March 4, 2024)
- Exploit #9339 - laravel-CVE-2021-3129-EXP () (September 18, 2023)
- Exploit #9242 - CVE-2021-3129 (CVE-2021-3129 | Laravel Debug Mode Vulnerability) (August 9, 2023)
- Exploit #8858 - ENSIMAG_EXPLOIT_CVE2_3A (Ensimag 3A - Exploit on CVE 2021-3129) (February 21, 2023)
- Exploit #8658 - Laravel-debug-Checker (CVE-2021-3129 Exploit Checker By ./MrMad) (December 11, 2022)
- Exploit #8463 - CVE-2021-3129 (CVE-2021-3129-Laravel Debug mode) (October 12, 2022)
- Exploit #8352 - Laravel-CVE-2021-3129 (CVE-2021-3129 POC) (September 7, 2022)
- Exploit #8268 - CVE-2021-3129-Script (Add revert shell ) (August 20, 2022)
- Exploit #7997 - Laravel-CVE-2021-3129 (CVE-2021-3129 POC) (June 9, 2022)
- Exploit #7669 - CVE-2021-3129 (Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)) (April 19, 2022)
- Exploit #7357 - Unauthenticated remote code execution in Ignition (February 16, 2022)
- Exploit #6991 - CVE-2021-3129 () (November 8, 2021)
- Exploit #6933 - CVE-2021-3129 (CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞) (October 24, 2021)
- Exploit #6811 - CVE-2021-3129 (PoC for CVE-2021-3129 (Laravel)) (October 1, 2021)
- Exploit #6804 - Laravel-8.4.2-rce-CVE-2021-3129 () (September 29, 2021)
- Exploit #6562 - laravel-CVE-2021-3129-EXP () (July 25, 2021)
- Exploit #5532 - Laravel_CVE-2021-3129_EXP () (June 6, 2021)
- Exploit #5430 - CVE-2021-3129 (Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)) (May 18, 2021)
- Exploit #5429 - CVE-2021-3129 (Laravel debug rce) (May 18, 2021)
- Exploit #5423 - laravel-CVE-2021-3129-EXP () (May 18, 2021)
- Exploit #5193 - Code Injection (March 7, 2021)
- Exploit #5086 - CVE-2021-3129_exploit (Exploit for CVE-2021-3129) (January 28, 2021)
- Exploit #5043 - laravel-exploits (Exploit for CVE-2021-3129) (January 19, 2021)