MEDIUM5.3
GHSA-rv74-mh27-4jpv
browsershot local file inclusion vulnerability
Quick fix
GHSA-rv74-mh27-4jpv — spatie/browsershot: upgrade to the fixed version with the command below.
composer require spatie/browsershot:^3.40.1Details
This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/spatie/browsershot
Introduced in:
0Fixed in: 3.40.1Fix
composer require spatie/browsershot:^3.40.1References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7790[ADVISORY]
- https://github.com/spatie/browsershot/issues/441%23issue-735049731[WEB]
- https://github.com/spatie/browsershot/pull/440[WEB]
- https://github.com/spatie/browsershot/commit/8d4bcfb1ff609921007f3fc11d80fcdad35598ac[WEB]
- https://snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-1037064[WEB]