Vulnerabilities
Vulnerable Software
Spatie:  >> Browsershot  Security Vulnerabilities
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
CVSS Score
8.2
EPSS Score
0.001
Published
2022-11-25
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.
CVSS Score
8.2
EPSS Score
0.001
Published
2022-11-25
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
CVSS Score
8.2
EPSS Score
0.001
Published
2022-11-25
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
CVSS Score
5.3
EPSS Score
0.003
Published
2020-12-11


Contact Us

Shodan ® - All rights reserved