PT-2024-40382 · Unknown · Endroid/Qr-Code-Bundle

Published

2024-05-15

·

Updated

2024-05-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions endroid/qr-code-bundle versions prior to 3.4.2
Description The issue arises from the improper handling of non-image data as the logo, which could lead to unintended file disclosure through the logo path query parameter.
Recommendations For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the logo path query parameter to minimize the risk of exploitation.

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-MVF6-3F2G-XFXF

Affected Products

Endroid/Qr-Code-Bundle