Описание
browsershot local file inclusion vulnerability
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
Ссылки
Пакеты
Наименование
spatie/browsershot
composer
Затронутые версииВерсия исправления
< 3.40.1
3.40.1
Связанные уязвимости
CVSS3: 5.3
nvd
около 5 лет назад
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.