Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2r4-phv7-5fgv

Опубликовано: 13 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.6
CVSS3: 8.6

Описание

Browsershot Local File Inclusion

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.

Пакеты

Наименование

spatie/browsershot

composer
Затронутые версииВерсия исправления

< 5.0.1

5.0.1

EPSS

Процентиль: 43%
0.00209
Низкий

6.6 Medium

CVSS4

8.6 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.6
nvd
около 1 года назад

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.

EPSS

Процентиль: 43%
0.00209
Низкий

6.6 Medium

CVSS4

8.6 High

CVSS3

Дефекты

CWE-20