CVE-2024-21549

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 20, 2024
Updated: Feb 4, 2025
CWE ID 125
CWE ID 20

Summary

CVE-2024-21549 is a newly disclosed vulnerability affecting versions of the package spatie/browsershot prior to 5.0.3. This issue involves Improper Input Validation due to insufficient URL validation through the setUrl method. An attacker can exploit this flaw by employing view-source:file://, enabling arbitrary file reading on a local file system. Notably, this vulnerability bypasses the fix for CVE-2024-21544.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share