Impact
The Laravel package disables TLS certificate verification by default, setting ssl_verify_peer to FALSE. This allows an attacker to present any certificate, intercept Google Maps web-service requests, steal the API key included in the query string, and tamper with responses, leading to credential theft and data manipulation.
Affected Systems
The Vulnerability affects the alexpechkarev/google-maps Laravel package up through version 12.16. Any deployment of these versions that relies on the bundled configuration is susceptible.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity impact. No EPSS data is available and the vulnerability is not listed in CISA KEV. The likely attack vector is an on-path attacker who can supply a forged certificate to the client; the vulnerabilities arise from the default configuration that disables peer verification, enabling MITM attacks and key exposure.
OpenCVE Enrichment