Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arbitrary File Read
Vulnerability Description
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Spatie Browsershot 路径遍历漏洞
Vulnerability Description
Spatie Browsershot是Spatie团队的一个基于Php、Javascript可将浏览器浏览页转换成PDF或图片格式的代码库。 spatie/browsershot from 0.0.0存在安全漏洞,该漏洞源于通过在文件:协议中指定URL,攻击者可利用该漏洞可以在生成的PDF中包含任意文件。
CVSS Information
N/A
Vulnerability Type
N/A