Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example.
By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Laragon
Laragon laragon
CPEs cpe:2.3:a:laragon:laragon:*:*:*:*:*:*:*:*
Vendors & Products Laragon
Laragon laragon

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Leokhoa
Leokhoa laragon
CPEs cpe:2.3:a:leokhoa:laragon:*:*:*:*:*:*:*:*
Vendors & Products Leokhoa
Leokhoa laragon
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 10 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin. Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.
Weaknesses CWE-434

Thu, 29 Aug 2024 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2024-10-10T15:36:13.513Z

Reserved: 2024-01-24T17:02:03.945Z

Link: CVE-2024-0864

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.878Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T13:15:07.260

Modified: 2025-04-24T17:01:31.400

Link: CVE-2024-0864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.