{"id":"GHSA-mvf6-3f2g-xfxf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mvf6-3f2g-xfxf","summary":"endroid/qr-code-bundle File Disclosure via logo_path query parameter","details":"Versions of endroid/qr-code-bundle prior to 3.4.2 are affected by a security vulnerability that allows disclosure of files through the logo_path query parameter. The vulnerability arises from the improper handling of non-image data as the logo, which could lead to unintended file disclosure.","published":"2024-05-15T21:05:13Z","modified":"2024-11-29T05:37:08.887462Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"endroid/qr-code-bundle","fixedVersion":"3.4.2"}],"fix":{"url":"https://github.com/endroid/qr-code-bundle/commit/51928eaaa30e7db1fd3f1076744dcbc8f8cec8c8","label":"endroid/qr-code-bundle@51928ea"},"references":[{"type":"WEB","url":"https://github.com/endroid/qr-code-bundle/commit/51928eaaa30e7db1fd3f1076744dcbc8f8cec8c8"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/endroid/qr-code-bundle/2019-12-22.yaml"},{"type":"PACKAGE","url":"https://github.com/endroid/qr-code-bundle"},{"type":"WEB","url":"https://github.com/endroid/qr-code-bundle/releases/tag/3.4.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:37:08.887462Z"}}