CVE-2023-36825
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deserialization of untrusted data from the `_state` query parameter, which can result in remote code execution. The issue has been addressed in version 14.5.0. Users are advised to upgrade their software to this version or any subsequent versions that include the patch. There are no known workarounds.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- orchid/platform
- Source
- security-advisories@github.com
References
- https://github.com/orchidsoftware/platform/releases/tag/14.5.0Release Notes
- https://github.com/orchidsoftware/platform/security/advisories/GHSA-ph6g-p72v-pc3pVendor Advisory
- https://github.com/orchidsoftware/platform/releases/tag/14.5.0Release Notes
- https://github.com/orchidsoftware/platform/security/advisories/GHSA-ph6g-p72v-pc3pVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.