Laravel 是一个 Web 应用框架。在 12.60.0 和 13.10.0 版本之前,Laravel 的电子邮件验证中存在 CRLF 注入漏洞。结合 Symfony Mailer 和 Symfony Mime 对某些字符序列的处理方式,该漏洞可能允许未认证的 attackers 干扰向用户提供的地址发送邮件的处理流程。该问题已在 12.60.0 和 13.10.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet