Lucene search

K
cvelistFluid AttacksCVELIST:CVE-2022-41706
HistoryNov 25, 2022 - 12:00 a.m.

CVE-2022-41706

2022-11-2500:00:00
Fluid Attacks
www.cve.org
browsershot
remote access
file validation
url protocol

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Browsershot",
    "versions": [
      {
        "version": "3.57.2",
        "status": "affected"
      }
    ]
  }
]

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Related for CVELIST:CVE-2022-41706