Headline
CVE-2023-29931: Local File Inclusion (LFI) vulnerability · Issue #437 · hhxsv5/laravel-s
laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
When the settings “handle_static” is true, LaravelS is affected by a LFI vulnerability.
public function handleStatic(IlluminateRequest $request) { $uri = $request->getRequestUri(); if (isset(self::$staticBlackList[$uri])) { return false; } $uri = (string)str_replace("\0", '’, urldecode($uri));
$requestFile = $this\->conf\['static\_path'\] . $uri;
if (is\_file($requestFile)) {
return $this\->createStaticResponse($requestFile, $request);
}
...
Related news
GHSA-q2fp-jw87-86px: laravel-s vulnerable to Local File Inclusion
laravel-s prior to 3.7.36 is vulnerable to Local File Inclusion via `/src/Illuminate/Laravel.php`.