TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2024-47049

HIGH
8.2

Beschreibung

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.

CVE Details

CVSS v3.1 Bewertung8.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht9/17/2024
Zuletzt geandert3/18/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

czim:file-handling

Schwachen (CWE)

CWE-22CWE-918CWE-22CWE-918

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.