Laravel - PHP Object Injection - 4.1, 4.2, 5.0, master From: Scott Arciszewski <scott () paragonie com> Date: Sun, 19 Apr 2015 14:12:23 -0400 Hi FD Readers, If you're using cookie-based session storage with any version of the Laravel Framework since 4.1 (inclusive), and you turned encryption off (I can't imagine why anyone would do that, but I've seen some weird setups), you are vulnerable to PHP