← back
CVE-2024-55556

CVE-2024-55556

CVSS 9.8 CRITICALEPSS 43.6%CWE-502
Vexday Risk Score
55Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 43.6%KEV nãoPoC Nuclei Metasploit simPatch
Lifecycle
13 Dec 2024Metasploit module available
07 Jan 2025Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution (RCE). The vulnerability is primarily exploited by accessing an exposed cookie and manipulating it using the secret key to gain malicious access to the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →