为 Backpack(一组用于构建自定义管理面板的 Laravel 包)提供创建、读取、更新和删除(CRUD)功能。在 4.1.70、5.6.2、6.8.13 和 7.0.36 版本之前, (位于 )通过 被调用,并使用受 HTTP 请求头影响的 URL 构造了一个 shell 命令,然后未经充分的 shell 转义就将其传递给 函数执行。 当系统中可用 和 命令,且命中“百分之一百”的随机门控条件时,未认证的 attackers 可以通过构造畸形的 值注入操作系统命令。通过重复发送请求,可以反复触发该随机门控。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Laravel-Backpack | CRUD | < 4.1.70 |
affected |
>= 5.0.0, < 5.6.2 |
affected | ||
>= 6.0.0, < 6.8.13 |
affected | ||
>= 7.0.0, < 7.0.36 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Laravel-Backpack | CRUD | < 4.1.70 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54178 | 8.1 HIGH | backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUpload |
| CVE-2026-54175 | 7.6 HIGH | backpack/crud: Unverified password change in MyAccountController via mass assignment |
| CVE-2026-54180 | 7.6 HIGH | backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cr |
| CVE-2026-54177 | 6.6 MEDIUM | backpack/crud: HasUploadFields keeps the attacker-supplied file extension — public-disk up |
| CVE-2026-54176 | 6.5 MEDIUM | backpack/crud: MyAccountController allows changing the login email without a current-passw |
| CVE-2026-57570 | 6.5 MEDIUM | backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (I |
| CVE-2026-54181 | 5.4 MEDIUM | backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches are |
No comments yet