Local File Exposure in Browsershot by Spatie
CVE-2022-43983
8.2HIGH
What is CVE-2022-43983?
Browsershot version 3.57.2 is susceptible to a vulnerability that permits external attackers to remotely access arbitrary local files. This flaw arises from the application's failure to validate HTML content supplied to the Browsershot::html method, allowing URLs that employ the file:// protocol. Consequently, this loophole could lead to unauthorized data exposure and raise significant security concerns for users of the product.
Affected Version(s)
Browsershot 3.57.2