Skip to content

endroid/qr-code-bundle File Disclosure via logo_path query parameter

Moderate severity GitHub Reviewed Published May 15, 2024 to the GitHub Advisory Database • Updated May 15, 2024

Package

composer endroid/qr-code-bundle (Composer)

Affected versions

< 3.4.2

Patched versions

3.4.2

Description

Versions of endroid/qr-code-bundle prior to 3.4.2 are affected by a security vulnerability that allows disclosure of files through the logo_path query parameter. The vulnerability arises from the improper handling of non-image data as the logo, which could lead to unintended file disclosure.

References

Published to the GitHub Advisory Database May 15, 2024
Reviewed May 15, 2024
Last updated May 15, 2024

Severity

Moderate

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-mvf6-3f2g-xfxf
Checking history
See something to contribute? Suggest improvements for this vulnerability.