Aller au contenu

Fiche vulnérabilité

CVE-2024-47049 : faille élevée czim file-handling (CVSS 8.2)

Description

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.

En bref

Sévérité
Élevée (CVSS 8.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
17 sept. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • czim file-handling

Références

Rechercher une autre vulnérabilité dans la base CVE