Laravel 8.4.2 in debug mode with Ignition 2.5.1, vulnerable to CVE-2021-3129: the MakeViewVariableOptionalSolution endpoint runs file_get_contents and file_put_contents on a user path, which, with php://filter tricks on the log file, triggers a phar deserialization and runs code.
Not startedDockercommit b58fb09x86_64 · aarch64Secret
Exploit CVE-2021-3129 to run commands on the Laravel server and get a shell.
The brief for this lab lives in its repository.