CVE-2024-47049

HIGH

czim/file-handling <1.5.0, <2.3.0 - SSRF & Path Traversal

Title source: llm
STIX 2.1

Description

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.

References (1)

Core 1

Scores

CVSS v3 8.2
EPSS 0.0063
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-918
Status published
Products (2)
czim/file-handling < 1.5.0
czim/file-handling 0 - 1.5.0Packagist
Published Sep 17, 2024
Tracked Since Feb 18, 2026