CVE-2024-21544

CVSS V2 None CVSS V3 None
Description
Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.
Overview
  • CVE ID
  • CVE-2024-21544
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-13T05:00:14.744Z
  • Last Modified Date
  • 2024-12-13T05:00:14.744Z
History
Created Old Value New Value Data Type Notes
2024-12-13 13:36:16 Added to TrackCVE