ZeroHour

CVE-2024-47049

CVSS 3.1
8.2 high
EPSS
<1%p48
Published
()
Modified
Description

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.

Vendors
czim
Products
file-handling
Weakness
CWE-22, CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.