CVE-2024-47049

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:czim:file-handling:*:*:*:*:*:*:*:*
cpe:2.3:a:czim:file-handling:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-17 14:15

Updated : 2025-03-18 20:15


NVD link : CVE-2024-47049

Mitre link : CVE-2024-47049

CVE.ORG link : CVE-2024-47049


JSON object : View

Products Affected

czim

  • file-handling
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-918

Server-Side Request Forgery (SSRF)