Miggo Logo

CVE-2025-26159:
Laravel Starter Cross Site Scripting (XSS)

6.1

CVSS Score
3.1

Basic Information

EPSS Score
0.10959%
Published
4/22/2025
Updated
4/22/2025
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
nasirkhan/laravel-startercomposer< 11.11.011.11.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided commit information for version 11.11.0 (commit 959161aacdd5ea0036c6117de9a72d742f40caed) does not contain any changes related to the 'tags' feature or sanitization of the 'name' field, which is where the XSS vulnerability is described to exist. The changes in the commit are primarily dependency updates and modifications to asset files, with a minor change in UserController.php related to password updates, which is not relevant to the described XSS in the tags feature. Without a clear patch in the commit addressing the XSS in the tags' name field, or access to the codebase of versions prior to 11.11.0, it's not possible to confidently identify the specific vulnerable functions based on the provided information. The vulnerability would likely reside in the controller methods responsible for storing, updating, and displaying tags, but these cannot be confirmed from the given data.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

L*r*v*l St*rt*r **.**.* is vuln*r**l* to *ross Sit* S*riptin* (XSS) in t** t**s ***tur*. *ny us*r wit* t** **ility o* *r**t* or mo*i*y t**s **n inj**t m*li*ious J*v*S*ript *o** in t** n*m* *i*l*.

Reasoning

T** provi*** *ommit in*orm*tion *or v*rsion **.**.* (*ommit ****************************************) *o*s not *ont*in *ny ***n**s r*l*t** to t** 't**s' ***tur* or s*nitiz*tion o* t** 'n*m*' *i*l*, w*i** is w**r* t** XSS vuln*r**ility is **s*ri*** to