This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2020-12-11T10:50:14.306775Z
Updated: 2024-09-16T23:11:42.099Z
Reserved: 2020-01-21T00:00:00
Link: CVE-2020-7790
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-11T11:15:11.540
Modified: 2024-11-21T05:37:48.503
Link: CVE-2020-7790
Redhat
No data.