Impact
Request::buildRequestUrl() in canto-saas-api concatenates path variables without encoding each segment, including scheme and contentId values used by GetContentDetailsRequest. If an application supplies an untrusted path variable, insertion of path traversal sequences, query delimiters, or fragment delimiters can alter the destination endpoint before AbstractEndpoint::sendRequest() attaches the authentication token. An attacker controlling that path variable can cause unintended reads or writes on the same Canto instance using the configured application's privileges, while applications that provide only trusted and validated identifiers remain safe. This issue is fixed in version 3.0.0.
Affected Systems
The Canto SaaS API PHP client library developed by jleehr is affected. All releases prior to version 3.0.0 are vulnerable. Version 3.0.0 and later include the fix that properly encodes each path segment.
Risk and Exploitability
The flaw has a CVSS score of 4.8, indicating moderate impact. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability allows an attacker who can control a path variable in an authenticated request to redirect the request to unintended endpoints, potentially enabling unintended reads or writes on the Canto instance using the application's privileges. The flaw is classified as CWE-74 and CWE-918 and was addressed in version 3.0.0.
OpenCVE Enrichment
Github GHSA