https://seclists.org/oss-sec/2025/q1/195: [SBA-ADV-20241209-01] CVE-2024-13918: Laravel 11.9.0-11.35.1 flected XSS via quest Parameter in Debug-Mode Error Page
Published Mar 10, 2025
·Updated
Affected Software
1 affected component
Laravel Framework>=11.9.0<=11.35.1
Frequently Asked Questions
1
What is the severity of CVE-2024-13918?
CVE-2024-13918 has a medium severity rating due to its potential for reflected XSS attacks.
2
How do I fix CVE-2024-13918?
To address CVE-2024-13918, you should upgrade to Laravel version 11.35.2 or later.
3
What type of vulnerability is CVE-2024-13918?
CVE-2024-13918 is identified as a reflected cross-site scripting (XSS) vulnerability.
4
In which versions of Laravel is CVE-2024-13918 present?
CVE-2024-13918 affects Laravel versions 11.9.0 to 11.35.1.
5
What can an attacker achieve with CVE-2024-13918?
An attacker can exploit CVE-2024-13918 to execute scripts in the context of the user's session via the debug-mode error page.