ephort/laravel-user-enumeration-demo

ephort/laravel-user-enumeration-demo

Releases0
Stars5
This repo contains demo code that was used to exploit user enumeration vulnerability in Laravel

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.