Impact
Backpack‑CRUD, a Laravel package suite for admin panels, has a flaw in Stats::makeCurlRequest. The method concatenates an attacker‑controlled HTTP Host header into a shell command that is passed to exec() without proper sanitization. When exec() and curl are available, an unauthenticated attacker can trigger a 1‑in‑100 “random gate” by sending repeated requests. If the gate opens, arbitrary OS commands run as the web‑server user, exposing environment secrets, files, and enabling data modification or service disruption.
Affected Systems
All releases of Laravel‑Backpack:CRUD before 4.1.70, 5.6.2, 6.8.13, and 7.0.36 are affected. These are the versions that have not yet applied the vendor‑supplied patch.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as High severity. The EPSS score of less than 1% indicates a low probability of exploitation, but the vulnerability is not in CISA’s KEV catalog. A remote attacker can exploit the flaw over the network with no authentication by sending crafted Host headers. Repeated requests allow the attacker to hit the random gate, executing arbitrary OS commands as the web‑server user, which can lead to credential theft, data tampering, or denial of service.
OpenCVE Enrichment
Github GHSA