Browsershot version 3.57.3 vulnerable to improper input validation
Moderate severity
GitHub Reviewed
Published
Nov 25, 2022
to the GitHub Advisory Database
•
Updated Apr 28, 2023
Description
Published by the National Vulnerability Database
Nov 25, 2022
Published to the GitHub Advisory Database
Nov 25, 2022
Reviewed
Dec 2, 2022
Last updated
Apr 28, 2023
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
References