CVE-2023-24249 is an arbitrary file upload vulnerability in laravel-admin v1.8.19. The flaw allows attackers to upload crafted PHP files to the server, which can then be executed, leading to remote code execution. The vulnerability arises from insufficient validation of uploaded files, permitting the upload of executable PHP code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin v1.8.19. The main file, CVE-2023-24249.py, is a Python script that automates the exploitation process: it logs into the target application using hardcoded admin credentials, retrieves CSRF tokens, and uploads a PHP web shell disguised as an image file via a vulnerable endpoint. Upon successful upload, the script extracts the path to the shell and prints its URL. The uploaded shell allows remote command execution by sending HTTP requests with the 'c' parameter. The README.md provides context, usage instructions, and an example of post-exploitation shell access. The exploit targets a web application accessible at http://admin.usage.htb and requires valid admin credentials. The repository is structured simply, with one exploit script and a README, and is intended for demonstration and testing against the vulnerable version of laravel-admin.
This repository contains a Python exploit script (exploit.py) targeting CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin v1.8.19. The exploit automates the process of authenticating to the admin panel (using provided credentials), uploading a PHP reverse shell via the vulnerable file upload endpoint, and then executing the shell to establish a reverse connection to the attacker's machine. The script requires the attacker to provide the target URL, valid admin credentials, and the attacker's IP and port for the reverse shell. The main code file is exploit.py, which uses the requests and BeautifulSoup libraries to interact with the web application. The exploit is operational, as it provides a working payload and automates the exploitation process. The README.md provides detailed usage instructions, including example commands and expected output. The endpoints involved are the admin login, settings (for file upload), and the uploads directory where the shell is placed. No hardcoded IPs or domains are present; all are provided as arguments. The repository is focused, containing only the exploit script, a README, and a license.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.