CVE-2024-21547
18.12.2024, 06:15
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.
Awaiting analysis
This vulnerability is currently awaiting analysis.