{"id":"GHSA-2gq2-m628-33xp","summary":"gregwar/rst Local File Inclusion Vulnerability","details":"A Local File Inclusion (LFI) vulnerability has been discovered in the gregwar/rst library, potentially exposing sensitive files on the server to unauthorized users. The issue arises from inadequate input validation, allowing an attacker to manipulate file paths and include arbitrary files.","modified":"2024-11-29T05:41:31.850172Z","published":"2024-05-15T21:49:20Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:49:20Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/Gregwar/RST/pull/34"},{"type":"WEB","url":"https://github.com/Gregwar/RST/commit/e8d90ccbeddd91ba3abc506079661dce234f9870"},{"type":"WEB","url":"https://hackerone.com/reports/179034"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/gregwar/rst/2016-10-31.yaml"},{"type":"PACKAGE","url":"https://github.com/Gregwar/RST"}],"affected":[{"package":{"name":"gregwar/rst","ecosystem":"Packagist","purl":"pkg:composer/gregwar/rst"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3"}]}],"versions":["v1.0.0","v1.0.1","v1.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-2gq2-m628-33xp/GHSA-2gq2-m628-33xp.json"}}],"schema_version":"1.9.0"}