{"id":"GHSA-2gq2-m628-33xp","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2gq2-m628-33xp","summary":"gregwar/rst Local File Inclusion Vulnerability","details":"A Local File Inclusion (LFI) vulnerability has been discovered in the gregwar/rst library, potentially exposing sensitive files on the server to unauthorized users. The issue arises from inadequate input validation, allowing an attacker to manipulate file paths and include arbitrary files.","published":"2024-05-15T21:49:20Z","modified":"2024-11-29T05:41:31.850172Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"gregwar/rst","fixedVersion":"1.0.3"}],"fix":{"url":"https://github.com/Gregwar/RST/pull/34","label":"Gregwar/RST#34"},"references":[{"type":"WEB","url":"https://github.com/Gregwar/RST/pull/34"},{"type":"WEB","url":"https://github.com/Gregwar/RST/commit/e8d90ccbeddd91ba3abc506079661dce234f9870"},{"type":"WEB","url":"https://hackerone.com/reports/179034"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/gregwar/rst/2016-10-31.yaml"},{"type":"PACKAGE","url":"https://github.com/Gregwar/RST"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:41:31.850172Z"}}