CyberRota Analysis
AI-GeneratedPrior to versions 4.12.0 and 5.7.0, Filament's handling of required fields in challenge forms for multi-factor authentication is flawed, allowing attackers to bypass app-based multi-factor authentication when recovery codes are enabled. This vulnerability poses a significant risk to applications utilizing Filament for Laravel development, particularly those relying on app-based authentication methods. Developers and organizations using affected versions should prioritize upgrading to the patched versions to mitigate potential security breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.