CVE-2020-7790

Published

Severity

CVSS v3:
N/A
CVSS v2:
5 MEDIUM

Description

This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:spatie:browsershot:*:*:*:*:*:*:*:*n/an/a*

External Links