Логотип exploitDog
bind:CVE-2025-3192
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3192

Количество 2

Количество 2

nvd логотип

CVE-2025-3192

10 месяцев назад

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-qw64-6vcc-8ghx

10 месяцев назад

Browsershot Server-Side Request Forgery (SSRF) via setURL() Function

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3192

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

CVSS3: 8.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-qw64-6vcc-8ghx

Browsershot Server-Side Request Forgery (SSRF) via setURL() Function

CVSS3: 8.2
0%
Низкий
10 месяцев назад

Уязвимостей на страницу