← Back

CVE-2024-47049

nvd nist
Published: Sep 17, 2024Modified: Mar 18, 2025

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: NVD

Description

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.

Affected (2)

Products: Czim: File Handling
1 product
File Handling
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Czim
Before 1.5.0
From 2.0.0 to 2.3.0

References (1)

Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.