CVE-2024-0864

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-0864
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0864.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-0864
Published
2024-02-29T13:15:07Z
Modified
2025-04-26T06:04:19.560035Z
Summary
[none]
Details

Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.

References

Affected packages

Git / github.com/leokhoa/laragon

Affected ranges

Type
GIT
Repo
https://github.com/leokhoa/laragon
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.5

3.*

3.1.9
3.2.3
3.3
3.3.2
3.4
3.5

4.*

4.0
4.0.10
4.0.11
4.0.12
4.0.14
4.0.15
4.0.4
4.0.9

5.*

5.0.0

6.*

6.0.0

Other

portable
untagged-4d721a4b2e1cf9ae1fb3