CVE-2022-41706 - CERT CVE
ID CVE-2022-41706
Sažetak Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Reference
CVSS
Base: 8.2
Impact: 4.7
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Zadnje važnije ažuriranje 29-04-2025 - 15:15
Objavljeno 25-11-2022 - 18:15