Laravel Ignition 未授权远程代码执行(通过文件上传)
在受影响的 Laravel Ignition 版本中,攻击者可以利用 file_get_contents() 和 file_put_contents() 的不安全使用来执行任意代码。此漏洞仅对使用调试模式的网站可被利用。
git clone https://github.com/cc3305/CVE-2021-3129.git --recursive --shallow-submodules。git submodule update --init --depth 1。