Description
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
iqzer0
References
www.exploit-db.com/exploits/49198 (ExploitDB-49198)
nova.laravel.com/ (Laravel Nova Official Homepage)
nova.laravel.com/releases (Laravel Nova Releases Page)
www.vulncheck.com/advisories/laravel-nova-range-dos (VulnCheck Advisory: Laravel Nova 3.7.0 - 'range' DoS)