Vulnerabilities > CVE-2020-24941 - Incorrect Authorization vulnerability in Laravel

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
laravel
CWE-863

Summary

An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.

Vulnerable Configurations

Part Description Count
Application
Laravel
590

Common Weakness Enumeration (CWE)