PT-2022-26035 · Unknown · Browsershot

Carlos Bello

·

Published

2022-11-25

·

Updated

2022-12-01

·

CVE-2022-41706

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Browsershot version 3.57.2
Description The issue allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Recommendations For Browsershot version 3.57.2, consider validating the URL protocol passed to the Browsershot::url method to prevent exploitation. As a temporary workaround, restrict access to the Browsershot::url method until a patch is available.

Exploit

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-41706
GHSA-8C2C-JXWJ-JQGF

Affected Products

Browsershot