HIGH7.5
GHSA-8wmw-prw8-2ggm
Craftql vulnerable to Server-Side Request Forgery
Details
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/markhuot/craftql
Introduced in:
0No fixed version published yet for markhuot/craftql (composer). Pin to a known-safe version or switch to an alternative.