
We found results for “”
CVE-2022-43984
Good to know:

Date: November 24, 2022
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
Language: PHP
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Top Fix

Upgrade Version
Upgrade to version spatie/browsershot - dev-analysis-6417pl;spatie/browsershot - dev-dependabot/github_actions/dependabot/fetch-metadata-2.2.0;spatie/browsershot - dev-dependabot/github_actions/dependabot/fetch-metadata-2.3.0;spatie/browsershot - dev-dependabot/github_actions/dependabot/fetch-metadata-2.0.0;spatie/browsershot - dev-dependabot/github_actions/dependabot/fetch-metadata-2.1.0;spatie/browsershot - dev-dependabot/github_actions/aglipanci/laravel-pint-action-2.5;spatie/browsershot - dev-dependabot/github_actions/aglipanci/laravel-pint-action-2.4;spatie/browsershot - dev-dependabot/github_actions/actions/checkout-3;spatie/browsershot - 0.1.0;spatie/browsershot - 3.57.4;acanto/laravel-frontend - 1.0.1;acanto/laravel-frontend - 0.2.12;acanto/laravel-frontend - 0.2.7;ngekoding/browsershot - 0.1.0;ngekoding/browsershot - dev-php5.6;koffleart/browsershot - dev-master;koffleart/browsershot - no_fix;stomaskov/browsershot - 0.1.0;stomaskov/browsershot - no_fix;info2soft/browsershot - no_fix;uwebpro/browsershot-stealth - v4.0.0;uwebpro/browsershot-stealth - dev-master;scratcher28/browsershot - 2.0.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | NONE |