Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2022-41706
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
0
Attacker Value
Unknown
CVE-2022-43984
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
0
Attacker Value
Unknown
CVE-2022-43983
Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.
0
Attacker Value
Unknown
CVE-2021-45040
Disclosure Date: March 17, 2022 (last updated October 07, 2023)
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
0
Attacker Value
Unknown
CVE-2020-7790
Disclosure Date: December 11, 2020 (last updated February 22, 2025)
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
0