CVE-2024-47049

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:czim:file-handling:*:*:*:*:*:*:*:*
cpe:2.3:a:czim:file-handling:*:*:*:*:*:*:*:*

History

27 Sep 2024, 17:09

Type Values Removed Values Added
CWE CWE-22
CWE-918
CPE cpe:2.3:a:czim:file-handling:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
First Time Czim
Czim file-handling
References () https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md - () https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md - Third Party Advisory

17 Sep 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-17 14:15

Updated : 2025-03-18 20:15


NVD link : CVE-2024-47049

Mitre link : CVE-2024-47049


JSON object : View

Products Affected

czim

  • file-handling
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-918

Server-Side Request Forgery (SSRF)