validation
Research Posts (2)
- Jun 12, 2021active_url validation check bypass in LaravelReported and fixed a vulnerability in Laravel where active_url validation rule could be bypassed in a situation where a target has a subdomain localhost.
- Jun 12, 2021POP Gadget using function injection in RequiredIfReported and fixed a vulnerability in Laravel where Illuminate\Validation\Rules\RequiredIf could be used as a gadget chain for deserialization vulnerabilities.