CVE-2018-6330: Laravel Framework

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Laravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.

Affected products

  • Laravel Framework: version 5.4.15 only

Published 2019-03-28. Last modified 2026-06-17.