By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Apr 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Laragon
Laragon laragon |
|
| CPEs | cpe:2.3:a:laragon:laragon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Laragon
Laragon laragon |
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leokhoa
Leokhoa laragon |
|
| CPEs | cpe:2.3:a:leokhoa:laragon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Leokhoa
Leokhoa laragon |
|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Thu, 10 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin. | Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin. |
| Weaknesses | CWE-434 |
Thu, 29 Aug 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-10-10T15:36:13.513Z
Reserved: 2024-01-24T17:02:03.945Z
Link: CVE-2024-0864
Updated: 2024-08-01T18:18:18.878Z
Status : Analyzed
Published: 2024-02-29T13:15:07.260
Modified: 2025-04-24T17:01:31.400
Link: CVE-2024-0864
No data.
OpenCVE Enrichment
No data.