yajra/laravel-datatables-oracle is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
88
High Risk
Affected versions of this package are vulnerable to Remote Code Execution due to improper handling of Blade templates. The vulnerability occurs because user-controlled template content is processed using the unsafe eval() function instead of the secure Blade::render() method. An attacker could exploit this by injecting malicious PHP code into a Blade template, which would then be executed with the application's privileges when the template is compiled. It could lead to complete compromise of the application server and underlying system.
You are affected if you are using a version that falls within the vulnerable range.
yajra/laravel-datatables-oracle is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in versions 5.11.7 - 12.5.1.
Upgrade the yajra/laravel-datatables-oracle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant