VDB
Sign up
HIGH7.5

GHSA-8wmw-prw8-2ggm

Craftql vulnerable to Server-Side Request Forgery

Details

Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/markhuot/craftql
Introduced in: 0

No fixed version published yet for markhuot/craftql (composer). Pin to a known-safe version or switch to an alternative.

References