Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files. **Note:** This is a bypass of the fix for [CVE-2024-21549](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
Spatie Browsershot 安全漏洞
Vulnerability Description
Spatie Browsershot是比利时Spatie团队的一个基于Php、Javascript可将浏览器浏览页转换成PDF或图片格式的代码库。 Spatie Browsershot 5.0.5之前版本存在安全漏洞,该漏洞源于容易受到不正确输入验证的攻击,导致本地文件包含允许攻击者读取敏感文件。
CVSS Information
N/A
Vulnerability Type
N/A