eval.blog

active_url validation check bypass in Laravel

Reported and fixed a vulnerability in Laravel where active_url validation rule could be bypassed in a situation where a target has a subdomain localhost.

References: