Описание
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files.
Note:
This is a bypass of the fix for CVE-2024-21549.
Ссылки
EPSS
Процентиль: 43%
0.0021
Низкий
8.6 High
CVSS3
Дефекты
CWE-20
Связанные уязвимости
EPSS
Процентиль: 43%
0.0021
Низкий
8.6 High
CVSS3
Дефекты
CWE-20