CVE-2022-2886 MEDIUM

CVE-2022-2886: Laravel deserialization

Vendor Unspecified
Product Laravel
Weakness CWE-502 · Unsafe deserialization
Published August 19, 2022
Last update April 15, 2025

CVSS base score

5.0/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

Description

A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-206688.

Key dates

Disclosure timeline

August 19, 2022 CVE published
April 15, 2025 Record updated