[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Laravel Nova 3.7.0 - (range) Denial Of Service Vulnerability

Author
iqzer0
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-35407
Category
web applications
Date add
04-12-2020
Platform
php
# Exploit Title: Laravel Nova 3.7.0 - 'range' DoS
# Exploit Author: iqzer0
# Vendor Homepage: https://nova.laravel.com/
# Software Link: https://nova.laravel.com/releases
# Version: Version v3.7.0
# Tested on: Manjaro / Chrome v83

An authenticated user can crash the application by setting a higher
value to the 'range' (default 30) parameter and sending simultaneous
requests (10 simultaneous requests was enough to DoS the server in my
testing)

Vulnerable URL:
https://example.com/nova-api/metrics/sum-orders?timezone=Indian%2FMaldives&twelveHourTime=true&range=3000000
Vulnerable Parameter: range

#  0day.today [2024-09-28]  #