Back

HIGH

Browsershot 3.57.2 - Server Side XSS to LFR via URL

Published Nov 25, 2022

Description

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Nov 25, 2022
Updated Dec 3, 2025
Reserved Sep 28, 2022
CISA Vulnrichment
Updated Apr 29, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-8C2C-JXWJ-JQGF