VDB
Sign up
MEDIUM

GHSA-3747-gjc9-vvg6

phpThumb is vulnerable to Server-Side Request Forgery (SSRF)

Quick fix

GHSA-3747-gjc9-vvg6 — james-heinrich/phpthumb: upgrade to the fixed version with the command below.

composer require james-heinrich/phpthumb:^1.7.12

Details

The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/james-heinrich/phpthumb
Introduced in: 0Fixed in: 1.7.12
Fixcomposer require james-heinrich/phpthumb:^1.7.12

References