VYPR
Critical severity9.6NVD Advisory· Published Jul 11, 2023· Updated Jun 17, 2026

CVE-2023-36825

CVE-2023-36825

Description

Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deserialization of untrusted data from the _state query parameter, which can result in remote code execution. The issue has been addressed in version 14.5.0. Users are advised to upgrade their software to this version or any subsequent versions that include the patch. There are no known workarounds.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
orchid/platformPackagist
>= 14.0.0-alpha4, < 14.5.014.5.0

Affected products

8
  • Orchid/Platform6 versions
    cpe:2.3:a:orchid:platform:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:orchid:platform:*:*:*:*:*:*:*:*range: >=14.0.1,<14.5.0
    • cpe:2.3:a:orchid:platform:14.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:orchid:platform:14.0.0:alpha4:*:*:*:*:*:*
    • cpe:2.3:a:orchid:platform:14.0.0:alpha5:*:*:*:*:*:*
    • cpe:2.3:a:orchid:platform:14.0.0:alpha6:*:*:*:*:*:*
    • cpe:2.3:a:orchid:platform:14.0.0:alpha7:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 14.0.0-alpha4, < 14.5.0
  • Range: >= 14.0.0-alpha4, < 14.5.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.