Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43984
HistoryNov 25, 2022 - 5:15 p.m.

Code injection

2022-11-2517:15:00
PRIOn knowledge base
www.prio-n.com
5
code injection
browsershot
remote obtain
arbitrary local files
external attacker
validate
js content
file protocol
nvd

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.

CPENameOperatorVersion
browsershoteq3.57.3

8 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.7%

Related for PRION:CVE-2022-43984